Fraud Risk Management

Fraud Risk Management

A resilient business does not rely on chance — where there is a threat, there must be a strategy. Fraud risk detection, prevention and mitigation services for companies in Ukraine.

Fraud risk management is a comprehensive systematic approach to identifying, assessing, monitoring and mitigating threats of fraudulent activity. It includes proactive controls, such as transaction monitoring, customer verification, implementation of internal policies, etc., to minimise financial losses, reputational damage and other adverse effects of fraudulent activity.

PwC offers end‑to‑end fraud prevention solutions covering the full fraud risk management cycle. With many years of experience and a deep understanding of the local environment, we help companies build a robust protection framework against both internal and external threats of fraud.

Key types of fraud 

The list below outlines the key types of fraud that are most relevant to the Ukrainian business environment:

< Back

< Back
[+] Read More

Why does fraud risk management matter for business?

Fraud rarely looks like an obvious theft. Most often, it manifests in gradual losses — through procurement kickbacks, inflated invoices and asset abuse that can remain undetected for years. Fraudulent activities pose risks to companies on multiple levels simultaneously: direct financial losses, reputational damage and legal consequences — all of which can cause serious damage even to resilient businesses and, in some cases, threaten their existence.

Companies that apply a proactive approach implement fraud risk management in their operating strategy. The objective is to identify vulnerabilities before they are exploited, rather than to respond to losses to reduce both the likelihood of fraud and the severity of its effects.

90%

of fraud cases relate to the asset misappropriation, which makes it the most widespread type of fraud

45%

of fraud cases include corrupt practices

6%

of cases relate to financial statement fraud, which, though less common, causes the highest financial losses

Effects of fraud: direct and hidden costs

The top 3 costliest types of fraud according to the ACFE Report:

$1,000,00

median losses caused by financial statement manipulation per case of fraud  

$150,000

median losses caused by corruption per case of fraud

$100,000

median losses caused by asset misappropriation per case of fraud 

The price a business pays when it does not manage fraud risks

Most executives see only the direct theft of money. However, the true cost of fraud runs much deeper:

Direct financial losses

Embezzlement and asset misappropriation

  • Misappropriation of cash from the cash register
  • Unauthorised bank transfers
  • Theft of goods and raw materials
  • False expenses and refunds

Inflated expenses due to corruption schemes

  • Kickbacks from suppliers (10–30% of the contract price)

  • Fictitious and inflated invoices

  • Procurement of low‑quality goods at the price of high‑quality ones

Lost profits

  • Loss of contracts due to a corrupt reputation

  • Unfavourable terms due to wrongful decisions made

Legal and regulatory costs

Litigations and investigations

  • Litigation expenses reaching millions in value for complex cases

  • Lawyer services

  • Expert evidence costs

Fines and sanctions

  • Tax sanctions (from 25% to 100% of the amount of tax abuse)

  • Regulatory fines (the NBU, the NSSMC, etc.)

  • Compliance irregularities (GDPR, AML and FCPA for multinational companies)

Compensation

  • Recovery of losses to affected parties

  • Shareholder compensation

Operational disruptions

Lost productivity

  • Distraction of management during investigations (hundreds of hours spent by top management)

  • Lower performance due to team demoralisation

  • Time needed to recover processes after fraud detection 

HR costs

  • Termination and replacement of compromised employees

  • Lost knowledge and expertise

  • Recruiting and onboarding costs for new joiners 

System failures

  • Downtime during investigations

  • Process rebuilding required

  • Implementation of new controls

Talent and corporate culture loss

Toxic effect on a team

  • Lower morale of a team after fraud detection

  • Management distrust

  • Talent drain (up to 25% of top performers may leave)

A culture of fear vs a culture of integrity

  • Suspicion and paranoia instead of collaboration

  • Concealment of errors by employees

  • Fostering a culture of integrity

Strategic losses

Lost opportunities

  • An inability to participate in tenders due to reputational risks

  • Counterparts’ refusal to cooperate

  • Blocking of entry to new markets

M&A issues

  • Impairment of a company value

  • Failed investor deals

  • IPO failures

Reputational damage

Lost customer confidence

  • Customer churn after high-profile fraud scandals

  • Sales drop after a public incident

  • 3-5 years taken to recover reputation

Lost investor confidence

  • Decline in stock value

  • Complicated investment raising process

  • Higher loan pricing

High-profile scandals in mass media

  • Negative publications staying in Internet forever

  • Viral impact in social media

  • Increasing reputation attacks by competitors


Our comprehensive fraud risk management services

We provide comprehensive services at each risk management stage – from preventive measures to fraud recovery – ensuring that a comprehensive approach is applied to business protection. PwC Forensic team possesses extensive fraud risk management expertise enabling to develop tailored solutions aligned with specific requirements of each organisation to enhance its protection and ethical culture. 

Fraud risk assessment and analysis

We conduct a comprehensive review of your organisation to identify its vulnerabilities and potential threats. A fraud risk assessment includes: 

  • Identification of potential fraud scenarios; 

  • Business process analysis to identify weak anti-fraud controls; 

  • Evaluation of corporate culture and tone from the top; 

  • Analysis of external risks (counterparties, suppliers, vendors and customers); 

  • Development of a prioritised fraud risk log; 

  • Support in the implementation of process and system changes to enhance protection from future threats.

Outcome/deliverable: A detailed report with recommendations, a risk heat map and a remediation plan.

Development of a fraud risk management system

We develop a fraud risk management system specifically tailored to your business needs: 

  • Anti-fraud policies and procedures; 

  • Design of internal controls; 

  • KRIs (Key Risk Indicators) for fraud monitoring;  

  • Support in selecting and implementing confidential channels of a whistleblowing hotline for employees to report suspicious actions as well as support in protecting whistleblowers; 

  • Counterparty due diligence procedures;

  • Development of recovery and improvement strategies, and provision of recommendations on remedial actions to resume normal operations and to eliminate the effects of fraud;

  • Support in the implementation of process and system changes to enhance protection from future threats; 

  • Employee training programmes.

Compliance with standards: ISO 37001 (Ant-bribery Management Systems), COSO Framework and ACFE international best practices.

Fraud investigations and forensic audits

Professional investigations of fraud incidents using advanced forensic techniques: 

  • Independent diagnostic conducted to detect and assess potential fraudulent schemes; 

  • Internal investigations of fraud incidents to establish root causes and the specific circumstances surrounding a discovered fraud; 

  • Data analysis to identify irregularities and fraud patterns; 

  • Interviews with suspects; 

  • Preparation of a body of evidence; 

  • Loss quantification and recovery pathway; 

  • Provision of management with relevant information on investigation findings and recommendations on further actions, including advice on potential prosecution of fraudsters. 

Strict confidentiality guaranteed. All investigations are conducted in full compliance with the Ukrainian legislation.

Transaction monitoring and analysis

We help companies create an effective and efficient transaction control framework and support them throughout its implementation:

  • Assessment of current monitoring systems;

  • Data analysis and identification of irregularities;

  • Preparation of further monitoring recommendations; 

  • Support in the technology vendor selection;

  • Control testing and gap analysis.

Integrity check (Due Diligence)

Integrity checks of counterparties, business partners and potential investees: 

  • Corporate intelligence and background checks;

  • Financial analysis and identification of red flags of fraud;

  • Sanction list and PEP screening; 

  • Reputation checks of UBOs and management;

  • Corruption and money laundering risk assessment.

Fraud prevention training for employees

We raise employee awareness of fraud risks:

  • Fraud prevention training of top management, finance function and controllers; 

  • Organising and delivering training to raise employee awareness of potential fraudulent schemes and relevant preventive methods;

  • Dedicated workshops (fraud detection, red flags); 

  • Development of training materials and case studies.


Key stages of implementation of a fraud risk management system

The implementation of a fraud risk management system is a comprehensive transformation that requires a structured plan, consistent communications and active engagement across the entire organisation. In order to build and implement an effective system, we apply a methodology based on international standards and best practices, which includes the following key stages:

Diagnostics

  • Gathering of information about the company processes

  • Identification of critical risk areas

  • Interviews with key employees

Analysis

  • Fraud risk assessment

  • Testing of existing controls

  • Data analysis and identification of irregularities

Support in solution development

  • Technology selection and implementation support

  • Development of policies and procedures

  • Development of an implementation plan

Implementation

  • Process and control setting

  • Employee training

  • Launch of a monitoring system

Support and monitoring

  • Regular performance checks

  • Risk assessment updates

  • System improvements


What companies need fraud risk management the most?

Financial characteristics

✓ High cash flow level: Large volumes of financial transactions create more opportunities for irregularities.

✓ Low profitability: Retail and distribution with margins of 3–5% — even 1% of fraud can wipe out a third of the profit.

✓ Significant inventory levels: Inventory is an easy target for theft and supplier‑related schemes.

✓ Complex calculations: Bonuses, commission fees and revenue share models — all create space for manipulation.

Operational characteristics

✓ Decentralised structure: Numerous branches/stores with autonomous management make control difficult.

✓ Geographical dispersion: International operations and remote regions — poor oversight.

✓ High employee turnover: Retail and HoReCa sectors constantly hire new staff, making it difficult to build a strong corporate culture.

✓ Cash transactions: Restaurants, petrol filling stations and retail points — cash settlements increase a risk significantly.

Industry factors

✓ Regulatory oversight: Financial services, pharmaceuticals and the public sector — fraud results not only in losses but also in regulatory sanctions.

✓ Reputational sensitivity: Brands and public companies — a fraud scandal can cause a collapse in market capitalisation.

✓ Competitive pressure: In a highly competitive environment, pressure to meet targets at any cost increases the likelihood of fraud.

Lifecycle and events

✓ Rapid growth: Fast business expansion often outpaces control agility.

✓ Mergers and acquisitions(M&A): Each transaction carries the risk of integrating third-party schemes and vulnerabilities that standard due diligence may fail to identify.  

✓ Preparation for IPO/sale: The identification of fraud incidents during investor checks may disrupt the transaction or lead to a reduction in valuation.   

✓ Leadership changes: Inherited schemes are the most susceptible to detection, yet they also pose the greatest risk to the new management team.  

✓ Financial difficulties: Companies in crisis face increased pressure on top management and employees, which elevates the risk of fraud — with growing incentives to “adjust” or manipulate figures at all levels.  


Industries with high risks of fraud


Banks and financial institutions

Common threats: 

Loan and payment card fraud

Money laundering

Internal fraud committed by employees

Why they are vulnerable: 

Complex financial products (loans or derivatives) create opportunities for irregularities

Regulatory requirements — fraud leads to the risk of losing a license

Employees’ internal access to customer accounts

Typical schemes: 

Loan fraud (fictitious borrowers or kickbacks from developers)

Insurance fraud (fictitious insurance claims or collusion with customers)

Insider trading and market manipulation

Money laundering facilitation


Retail

Common threats: 

Stealing of goods and shrinkage

Return fraud

Promo abuse

 

Why they are vulnerable: 

Large inventory stock with thousands of SKUs

Many points of sale that are difficult to control

Seasonal staff

Low profitability — even 2–3% fraud leads to operating at loss

Typical schemes: 

Vendor fraud (short deliveries and kickbacks for inclusion in the product mix)

Theft of goods by employees

Discount abuse (unauthorised discounts for acquaintances)

Return of stolen goods for cash

Manipulations with cash registers (cancellation of transactions after payment)

 


Manufacturing enterprises

Common threats: 

Procurement fraud

Theft of raw materials and finished goods

Vendor kickback schemes

Why they are vulnerable: 

Procurement of raw materials worth millions — significant amounts for kickback schemes

Complex supply chains with many intermediaries

Technical specifications — the procurement department may tailor requirements to favour a specific supplier

Typical schemes: 

Kickbacks from vendors (10–30% of the contract price)

Inflated prices for raw materials and components

Improper quality substitution (one grade is ordered, a cheaper one is delivered)

Fake intermediaries used to siphon off funds


Pharmaceuticals and Healthcare

Common threats: 

Falsification of documents

Corruption in procurement

Insurance claim fraud

Why they are vulnerable: 

High‑margin products (medications with a markup)

Regulatory requirements — fraud leads to loss of licences

Insurance benefits — overbilling potential

Typical schemes: 

Overbilling to insurance companies or the government for medical services

Kickbacks from pharmaceutical companies for prescribing specific medications

Counterfeit medicines entering the supply chain

Manipulation of clinical trial data


Public sector

Common threats: 

Tender corruption

Misuse of budget funds

Conflict of interests

Why they are vulnerable: 

Lack of profit‑driven motivation results in weaker financial discipline

Bureaucratic procurement processes create space for corruption

Political pressure to appoint loyal individuals

Public oversight creates reputational risks

Typical schemes: 

Tender bribery

Procurement fraud (inflated prices, fictitious suppliers)

Payroll fraud ("ghost" or fictitious employees)

Embezzlement 


Logistics and Transport

Common threats: 

Fictitious repair expenses

Fuel theft

Cargo theft

Why they are vulnerable: 

Goods in transit — it is difficult to track movements

Fuel expenses — large amounts that are easy to manipulate

Driver expenses — opportunities for fictitious expense schemes

Typical schemes: 

Inflated repair expenses (collusion with service stations)

Cargo theft involving drivers

Fuel theft or fictitious fuel purchases

Route manipulation for personal purposes


Real Estate and Construction

Common threats:

Kickbacks from contractors

Theft of construction materials

Overstated budgeted expenses

Bribery to obtain permits and approvals

Why they are vulnerable: 

Kickbacks from contractors

Theft of construction materials

Overstated budgeted expenses

Dependence on government permits creates corruption risks

Typical schemes: 

Kickbacks to contractors in exchange for winning contracts

Systematic theft of materials from construction sites

Overstated expenses in project estimates

Bribes to officials to expedite approval procedures


IT and Telecommunications

Common threats: 

Cyber fraud

System security breaches and information theft

Insider threats

Why they are vulnerable: 

Intellectual property — the core asset that is easy to copy and steal

Remote work and system access complicate control

Technical expertise enables employees to override security controls

Rapid technological advancement — security often lags behind innovation

Access to sensitive customer data creates opportunities for misuse

Typical schemes: 

Theft of source code to transfer it to competitors or to use it in personal projects

Selling customer databases to third parties

Fake providers of licence or service (inflated “consulting” or “licensing” fees)

Backdoor access

Expense fraud (disguising personal purchases as business equipment expenses)


Fraud risk management: common reasons for inaction

✘ "We have trustworthy people, fraud is impossible"

According to the ACFE, 85% of fraudsters are first‑time offenders with no prior criminal record. Even honest employees may commit fraud when three factors are present: opportunity, financial pressure and rationalisation (internal justification of their actions).

✘ "We have internal audit in place"

Internal audit focuses on compliance with procedures rather than on fraud detection. This requires different competencies, methodologies and work approaches.

✘ "We are a small business. Fraud is a problem only for large corporations"

The ACFE data shows that fraud occurs in organisations of all sizes, with cases distributed relatively evenly across company scales. The highest median losses are recorded in companies with 10,000+ employees. However, small businesses (less than 100 employees) are not an exception. For small businesses, losses are significantly more painful due to limited budgets, lower liquidity buffers and generally weaker internal controls.

✘ "It is expensive, we don’t have the budget"

Fraud costs companies around 5% of annual revenue on average (according to the ACFE data). For a company with USD 10 million in revenue, that amounts to USD 500,000 annually. Fraud risk management costs only a portion of this amount and pays off.


Practical advantages of implementing a fraud risk management system

Posylenyy zakhyst vid ryzykiv shakhraystva

Enhancement of protection against risks

A fraud risk management system helps identify weaknesses in general risk management strategies of an organisation, which allows taking remedial actions to eliminate them promptly.

Zmenshennya finansovykh vtrat

Reduction of financial losses

The effective system enables to detect potentially suspicious transactions or fraud schemes at early stages, helping reduce direct financial losses.

Investytsiyna pryvablyvist

Investment attractiveness

Investors, acquirers and underwriters assess the maturity of the internal control environment as part of the due diligence process. The existence of a documented fraud risk management system enhances confidence in the company and helps protect its valuation during funding rounds, M&A transactions or IPO preparation.

Pokrashchennya operatsiynoyi efektyvnosti

Improvement of operating performance

Implementing dedicated fraud detection technologies can automate and optimise internal processes, reducing audit timing and staff workload.

Zakhyst personalnoyi vidpovidalnosti

Mitigation of personal liability risk

In Ukraine and across international jurisdictions, executives and supervisory board members may incur personal liability for inadequate internal controls, including exposure to financial sanctions and criminal prosecution. A documented and implemented fraud risk management system serves as evidence of due diligence on the part of management and significantly reduces these risks.

Vidpovidnist zakonodavstvu

Regulatory compliance

Numerous regulators require organisations to have an internal control and risk management system in place, and a fraud risk management system can be an important part of this requirement.

Pidvyshchennya reputatsiyi

Enhancement of reputation

A consistent approach to fraud risk management demonstrates customers and investors that an organisation is committed to security and protection of its assets.

Dani dlya stratehichnykh rishen

Data for strategic decision making

Collecting and analysing data on fraud attempts can provide the valuable information about risks, enabling to develop more accurate forecasts and business development strategies.

Pobudova kultury dobrochesnosti

Fostering a culture of integrity

Regular personnel training and learning on fraud indicators and methods raise the company-wide awareness level, which contributes to a faster detection of potential threats.


Contuct us

Andriy Tretyak

CFE, CISA, Forensic and Financial Crime Leader, Kyiv, PwC in Ukraine

+380 44 354 0404

Email

Dariia Riabova

Senior Manager, Forensic Services, PwC in Ukraine

+380 44 354 0404

Email

Anastasiia Myroshnychenko

Manager, Forensic Services, PwC in Ukraine

+380 44 354 04 04

Email

What do we specialise in?

Fraud risk assessment

A thorough fraud risk assessment that accurately identifies the Organisation-specific fraud risks is one of the key mainstays for building an effective fraud risk management capacity and resilience to the risks of fraud. Such an assessment is not a one-off exercise, but rather the one that maximises its value for the Organisation when performed on a systematic and recurring basis.

As a part of fraud risk assessment we support Organisations with:

  • Identification and prioritisation of the areas and activities most prone to fraud based on their industry specifics, size, history of past fraud cases and other related matters;
  • Identification of inherent fraud risks faced by the Organisations and assessment of their likelihood and magnitude of potential impact;
  • Mapping existing internal controls to the relevant fraud risks and evaluation of whether they are operating effectively and efficiently;
  • Identification and evaluation of residual fraud risks resulting from poorly efficient or non-existent controls;
  • Prioritisation of the residual fraud risks based on their potential likelihood and scale of prospective impact;
  • Development of practical tailored recommendations in response to the identified residual fraud risks.

Enhancement of existing fraud management practices

Fraud risk management is an integral part of the overall risk management practices within the Organisation. It is based on the concept of tailored steps aimed at timely identification, analysis and response to fraud risks that could threaten the Organisation’s viability, solvency, reputation and capacity to create value.

We support Organisations with design, implementation and enhancement of fraud risk management frameworks through:

  • Review of existing fraud risk management policies, procedures, practices and tools and identification of areas for improvement;
  • Development of practical tailored recommendations on enhancement of existing fraud risk management practices including:
    • Streamlining of anti-fraud culture and tone from the top
    • Strengthening fraud prevention and detection controls
    • Introducing new or proposing changes to existing policies and procedures related to fraud risk management
    • Design of necessary organisational changes and communication / reporting lines
    • Providing practical advice on selection and implementation of automated solutions related to fraud risk management
    • Capacity building of designated personnel responsible for fraud risk management and raising awareness on related matters amongst the Organisation’s business partners and other key stakeholders (clients, vendors, distributors);
  • Support with design and effectuation of the necessary changes.

FAQs about fraud risk management

The cost is estimated on a case-by-case basis, resulting from a comprehensive analysis of your business. 

Cost drivers:

  • The scope of operations;

  • Industry specifics; 

  • Current maturity of controls;

  • Technological infrastructure;

  • History of incidents;

  • Project objectives and other considerations. 

We consider not just the size of the company, but the actual complexity of its risk landscape.

Timing is normally driven by the business readiness for change and the complexity of the current situation.

Timeline drivers:

  • Data availability — quality of accounting records, historical data accessibility and the level of process digitalisation;

  • Structural complexity — holdings with multiple legal entities, international operations or franchising models require more time to implement; 

  • Reluctance to change — the pace depends on a company’s culture and its team’s readiness for transformation;

  • Severity of the situation — if active fraud is detected, we work in an accelerated mode.

Realistic roadmap:

  1. “Diagnostic” Stage: Assessment of the most critical areas based on a red flags analysis. It provides an understanding of the extent of the problem and establishes a baseline for all metrics. 

  2. “In-depth Analytics” Stage: Comprehensive assessment of the risk landscape, control testing, interviews with key stakeholders and historical data analysis. We develop a detailed vulnerability map and an action plan.

  3. “System Design” Stage: Development of anti‑fraud policies, procedures, control activities and performance metrics. Adaptation of the system to your corporate culture and business realities.

  4. “Implementation Support” Stage: Support in setting technological solutions, integrating them with your existing systems and training your teams.

  5. “Stabilisation” Stage: Process tailoring to real‑life conditions, feedback-based adjustment, knowledge base establishment and ownership transfer to internal teams. 

The communication strategy is no less important than the technical part of the project. Incorrect communication can undermine trust or, conversely, encourage fraudsters to hide their tracks.

Each situation is unique and requires a tailored approach. The communication strategy is developed considering your business specifics, corporate culture and the specific circumstances. Below are several typical scenarios as examples of possible approaches:

Scenario 1: Preventive implementation (no suspicions exist)

Open communication is the best approach:

Positioning: Not “fighting fraudsters” but “protecting the company's interests and honest employees”;

Message: “We are creating a transparent environment where honest work is valued and protected”;

Engagement: Employees become part of the system — they are explained how to identify risks and where to report suspicions;

Cultural effect: An anti‑fraud culture is developed, where fraud becomes socially unacceptable.

Advantages of openness:

  • Preventive effect — potential fraudsters understand that the system operates properly;

  • Information crowdsourcing — employees become the company’s “eyes”;

  • Increased trust.

Scenario 2: Post-incident (after fraud has been detected)

Balanced communication:

Internal audience: Explain what has happened without going into details, what actions have been taken and how recurrence will be prevented.

Message: “The system operates properly, the fraudsters have been held accountable and the company is protected”;

Copycat prevention: Do not disclose details of the schemes;

Restoration of trust: Demonstrate that the company is in control of the situation.

Depending on the strategy, appropriate communication channels are used:

  • All‑hands meetings to shape the culture;

  • Targeted sessions for high‑risk departments;

  • Confidential whistleblowing hotline;

  • Regular reminders via internal communications;

  • Case studies (anonymised) for training.

Our role:

We help develop the communication strategy, prepare the key messages and provide HR and legal advice to management. If needed, we conduct communication sessions ourselves or train your leaders.

Yes, it is possible to analyse historical data for several years to identify anomalies that may have gone unnoticed. Fraud committed in prior periods is often easier to detect than ongoing fraud because the full picture is available, patterns are becoming more apparent and fraudsters tend to lose vigilance over time.

Why the historical analysis matters:

1. Fraud is rarely a one‑time event, most schemes involve systematic activity lasting months or years:

  • Escalation model: Fraudsters go slow (“testing the system”) and gradually expand the scope.

  • Dependence effect: The psychology of a fraudster — after succeeding for the first time, stopping becomes increasingly difficult.

  • Improved concealment: Over time, fraudsters “refine” their schemes and, consequently, early versions leave more evidence.

2. Statistical anomalies are visible only over long periods. A single suspicious transaction may appear accidental but a pattern of 50 similar transactions over 3 years constitutes evidence.

3. Hidden consequences of past fraud, even if the fraudster has left the company or the scheme has stopped, the effects remain. Examples of the consequences include:

  • Inflated prices from a “friendly” supplier becoming the norm, causing the company to continue overpaying;

  • Goods written off as “sold” but actually stolen — inventory records no longer match reality;

  • Past fictitious expenses triggering current questions from tax authorities;

  • Management decisions made based on manipulated accounts.

What can be analysed retrospectively:

Financial records

  • General Ledger: Accounting entries are a source for identifying manual adjustments, round-sum transactions and unusual accounts.

  • Accounts Payable: Payments to suppliers – an analysis for duplicate payments, fake suppliers, payments broken down to avoid approval limits.

  • Payroll: Identification of dummy employees, inflated wages and salaries, and unauthorised bonuses.

  • Expense reports: Trends in inflated expenses, fake business trips, personal expenses disguised as corporate.

  • Inventory movements: Differences between the purchases, sales and physical stock – an analysis of shortages.

Transaction data

  • Orders vs. Invoices vs. Payments: Three-way matching to identify any overpaid balances, counterfeit services or facilitation payment schemes.

  • Sales records: Discount fraud, revenue recognition manipulations, counterfeit sales recorded to achieve performance targets.

  • Bank transactions: Unusual cash movements, cash transactions and offshore transfers.

Digital traces (depending on the retention policy)

  • Email archives: Key evidence of collusion, instructions from fraudsters, negotiations with accomplices. Even deleted emails are often recoverable from backups.

  • Access logs: Who accessed the systems and when, particularly at unusual times (nighttime, weekends) or from unusual locations.

  • Document metadata: Who created/edited financial documents, when and how many times. Identifies backdating and unauthorised changes.

  • Messengers: Telegram, Slack, Teams – often have open discussions of various schemes (people feel a false sense of security in “informal” channels).

Practical limitations of the retrospective analysis

Data availability

  • Backup retention policies: Many companies retain backup copies for 1-2 years only. Any older data may be lost.

  • System migrations: After the migration to a new Enterprise Resource Planning (ERP) system, historical data is sometimes migrated incompletely or in a legacy format, which is difficult to analyse.

  • Paper documents: Old documents may be physically destroyed in line with the retention policy or “accidentally” lost.

Legal admissibility

  • Statute of limitations: Criminal liability for fraud in Ukraine is usually limited to 3-5 years. Revealing older schemes may be valuable for improving controls but not for criminal charges.

  • Evidence integrity: The older the data, the harder it is to prove its integrity to court (the chain of evidence retention, no tampering).

Cost vs. value:

An in-depth forensic audit covering multiple years may take hundreds of hours of analysts’ work. Balance is key:

  • Risk-based approach: We focus on high-risk areas (large amounts, weak controls, suspicious individuals). 

  • Sample-based review: Our detailed review covers a representative sample rather than 100% of transactions. 

  • Stage-by-stage analysis: We start from the most recent year and move deeper if we find any trends.

If you have suspicions about past incidents or require a full picture for strategic decisions, we are ready to perform an in-depth retrospective analysis meeting all legal requirements and confidentiality standards.

We support you throughout the process — from the collection and retention of evidence to the preparation of reports for legal proceedings and engagement with law enforcement agencies. Following the analysis, we provide a detailed plan to address any control weaknesses identified and assist in implementation of prevention measures.

 

The moment of fraud discovery is a critical point that determines whether you will be able to press charges against the fraudsters. Wrong steps at this stage may ruin any chances of punishment for the fraudsters or give rise to legal risks for the company. Let us look at the step-by-step guidance:

Stage 1: Record the evidence

Critical: Evidence must be recorded before the suspect finds out about the investigation in progress.

Priority focus:

  1. Forensic copies of data: Hard disks, email, corporate messengers, cloud storages. Make bit-stream copies verified using cryptographic hash values – this guarantees admissibility in court.

  2. Retain physical evidence: Documents, flash drives, personal belongings from the workstation are sealed.

  3. Revoke access: Restrict access to delete files – read-only mode for all critical systems.

  4. Record testimony: Collect testimony from any informed witnesses.

  5. Timeline reconstruction: Create a detailed timeline of events with each document and transaction.

Stage 2: Legal assessment and strategy selection

We will work with your legal team to identify:

Nature of the offence: Is it a crime, a civil infraction or a disciplinary offence?

Sufficiency of the evidence: Will it stand scrutiny in court?

Procedural clarity: Did you comply with all the applicable Labour Code requirements?

Any accomplices: Is it an individual offence or an organised group?

Stage 3: Response strategy

Choose the right path depending on the circumstances:

  • Criminal charges – substantial loss, clear signs of a crime, need for a deterrent effect. We prepare an evidence pack for police, support the investigation and concurrently prepare a civil lawsuit.
  • Civil lawsuit – when recovering the cash is a priority. We quantify the loss and support the court proceedings. Higher chances of real cash recovery, shorter timeframe.
  • Internal settlement – when the suspect is prepared to cover the loss and publicity would cause more harm. We structure the amicable agreement with a payment schedule and security.
  • “Quiet” exit – in case of minor loss, incomplete evidence or critical reputational risks.  We ensure there are clear grounds for dismissal.

Stage 4: Disciplinary proceedings

Ensure the dismissal is legally clear:  

  • Labour Code-compliant internal investigation;

  • The employee’s right to explanation;

  • Compliance with the time requirements (one month of the detection date);

  • Detailed documentation of each step.

Stage 5: Loss recovery

  • Identification of the suspect's assets (real estate, bank accounts, property)

  • Tracking of the stolen cash

  • Tackling the third-party cash recipients

  • Insurance claims (if covered by a policy)

  • Seizure of assets by court until the ruling

Stage 6: Systemic changes

  • Fraud is a signal of weak controls:

  • Root cause analysis – why the scheme became possible

  • Strengthened controls and automation

  • Updated policies and procedures

  • Employee training

  • Fostering a fraud zero-tolerance culture

Stage 7: Communications

Internal: Complete transparency with top management, limited information for employees.

External: Customers/partners notified only if affected, prepared media messages via the public relations team, mandatory notice for the regulators (for financial institutions).

Stage 8: Post-incident monitoring

  • Tracking whether the suspect appears at your competitors with your data

  • Whistleblower protection

  • Response effectiveness analysis

  • Full case file retained

Fraud is always stressful for any organisation. Our task is to minimise any losses (i.e. financial, reputational, emotional ones) on this journey to allow the company to emerge from the crisis stronger.

We provide a full scope of services to respond to fraud incidents – from evidence retention to litigation support. Our team includes forensic accountants, lawyers and investigation experts experienced in working with law enforcement agencies and courts.

We prepare evidence that withstands court scrutiny, develop a strategy to recover as many losses as possible and help you adopt systemic changes to prevent incident reoccurrence. Following the investigation, we issue a complete report with recommendations regarding the legal steps, disciplinary measures and control reinforcements.

We understand that you provide us with access to the company's most sensitive information, such as financial records, internal communications and employee files. This information is protected on the following levels:

  • Legal level: A non-disclosure agreement (NDA) is signed prior to commencing any engagement.

  • Technical level: Data is stored on secure encrypted servers. 

  • Organisational level: For the project, we engage only those required on a need-to-know basis.  

After the project is completed, all working papers are destroyed or returned to the client following the agreed protocol.

A performance assessment of existing fraud controls starts with a detailed review of relevant policies and procedures applied to prevent fraudulent activities. This includes checking those controls for adequacy and relevance as well as whether they are able to detect and prevent fraud. An organisation should perform an independent assessment of internal processes to identify whether controls are sufficiently reliable and to update them promptly in response to evolving risks.

An important aspect is the collection and analysis of data on past fraud incidents, if any, or on cases when controls could not have operated as intended. This can also include employee feedback on their experience of using the existing controls in practice. Regular tests of control procedures can identify weaknesses and prompt further improvements. An analysis of such data enables to adapt and streamline control tools, improving their effectiveness and adequacy for relevant challenges and risks. 

We help organisations assess the effectiveness of the existing controls to prevent fraud by carrying out comprehensive independent audits and tests of control procedures. We analyse adequacy and relevance of current policies, help identify weaknesses and provide recommendations for improvement.

Three dimensions of control effectiveness

1. Design Effectiveness: Is the control designed correctly to prevent or detect a specific risk?

What we check: 

  • Does the control cover the risk it was designed for?  

  • Is the performance frequency sufficient (daily, weekly, monthly)?   

  • Does the control performer have sufficient powers and competencies? 

  • Are there clear criteria of an exception in place?  

  • Is there a response protocol for identified issues?

Example: The Company has a control requiring an approval of all payments above UAH 50 thousand by CFO. 

  • Ineffective design: Approval happens post factum after cash has been paid.

  • Effective design: Approval before the payment is made in the system. 

2. Operating Effectiveness: Is the control performed as designed, systematically and reliably?

What we check: 

  • Is the control performed on a regular basis without omissions? 

  • Is there documented evidence of performance?  

  • Do responsible individuals respond to the exceptions identified?

  • Is the control overridden due to exceptional circumstances?  

  • Is the control performed as a formality or a tick-the-box exercise?

Example: The policy requires reconciling bank statements on a monthly basis. 

  • We check: Whether there are signed reconciliation statements for the latest 12 months.

  • We identify: 3 months were skipped while others were signed without any real checks. 

3. Control adaptability: Does the control remain relevant in response to business changes?

What we check: 

  • Are the controls updated as new products/processes are launched?

  • Are the controls adapted to new fraud techniques?  

  • Do they consider technological changes (new systems, automations)?

How we assess controls:

1. We analyse formal documentation: Policies and procedures, authority matrices, job descriptions, approval schemes, risk maps.

What we look for:

  • Gaps in risk coverage;

  • Outdated procedures that do not reflect reality; 

  • Authority conflicts (the same individual is able to initiate and approve).

2. Sampling – we take a representative sample of transactions and check them for the following:  

  • Are all the necessary approvals in place?  

  • Are the signatures in line with powers?   

  • Are appropriate supporting documents available?

  • Are the deadlines met? 

The size of the sample typically depends on the risk type.

3. Walkthrough testing – We walk through the entire process end-to-end – selecting a real transaction and tracing all steps from initiation to completion. We check whether controls work at each stage and identify any ‘grey areas’ where control is lacking. 

Example: We trace procurement from order to payment:

Order → Approval → Sourcing → Contracting → Arrival of goods → Invoice → Payment. 

At each stage, we check who performs, who controls and what is documented.

4. Interviews with responsible individuals performing controls: Do they understand what this control is for? What do they do if they encounter an issue? What challenges arise in performance of controls? How do they act in emergencies? 

5. Analytical procedures – we rely on the data analysis to identify any outliers.

6. Red Team Testing – we attempt overriding controls, e.g.: 

  • Can we create a counterfeit supplier? 

  • Can we approve a payment without appropriate documents? 

  • Can we modify bank details in the system?

  • Will the system identify duplicate accounts? 

Important from the ethical standpoint: We do this with management’s permission, in controlled conditions and without any real financial losses.

Prioritisation of control improvements

Not all the weaknesses identified are equally critical. We help prioritise control improvements depending on the level of risk and potential financial impact. Examples of priority categories are provided below:

Critical (address immediately): 

  • High financial risk + weak/non-existent control;

  • Uncontrolled cash transactions; 

  • Payments without appropriate approvals;

  • Access to systems without segregation of duties. 

High priority (address over several months):

  • Medium financial risk + weak control; 

  • Procurement beyond competitive procedures;

  • Inventory management without reconciliations; 

  • Irregular controls in high-risk areas.

Medium priority (address over 6 months):

  • Low financial risk + weak control;

  • Procedural weaknesses without direct impact on finance; 

  • Optimisation of existing controls.

A control assessment is a regular process. We recommend conducting a full-scope assessment at least once every several years and annually for high-risk areas. 

We perform an independent assessment of existing controls, policies and procedures to identify vulnerabilities that may be missed in-house. With our experience, we propose adapted best practices from other sectors, providing innovative fraud risk mitigation solutions. 

Being aware of potential fraud, organisations can promptly detect and prevent fraudulent activities. What should be focused on:

  1. Unusual financial transactions: Are there any transactions beyond usual arrangements? Transactions that do not align with the typical business model or normal financial flows (e.g., unusual transaction amounts, sudden changes in transaction frequency, or transactions conducted at atypical times).
  2. Mismatched financial records: Are there any account inconsistencies or unbalanced accounting reports or financial records that do not reconcile with stock counts?
  3. Excessive cancellations or changes: Is the high level of cancellations or changes in transactions or records observed? It is highly suspicious when the same individuals are involved.
  4. Missing documentation: Is there any transaction with missing documentation or justification or are there missing documents or records?
  5. Deviations from internal controls: Do employees, especially management, override established internal rules and policies on numerous occasions?
  6. Changes in the employees’ way of living: Do employees live spending more than they can afford or do any abrupt and unclear changes in their financial standing occur?
  7. Rapid staff rotation: Is a frequent change of employees, especially in a finance function, observed? This may prove problems existing in the function management or an intention to conceal unethical practices. 
  8. Supplier or customer complaints: Are there frequent complaints about inconsistencies in invoices, shipments or contracts? Such arrangements may provide evidence of fraudulent activities.
  9. Conflicts of interest: Are there any undisclosed relationships between employees and suppliers or customers that could indicate collusion or actions taken for their own gain?
  10. Excessive discretion regarding operational processes: Do employees overprotect their work and resist sharing information with others, particularly during audits?

The presence of one or two indicators is not evidence of fraud, but it is sufficient to warrant a professional risk assessment. A comprehensive fraud risk assessment within an organisation is one of the key components in building its capability to offset its adverse impacts effectively. The maximum effect of such an assessment is typically achieved when it is performed on a regular basis, considering the organisation’s specific characteristics as well as internal and external drivers. 

The effective and efficient implementation of a fraud risk management system requires robust planning, smooth communication and organisation-wide engagement. It starts with a comprehensive assessment of current risks including an identification of vulnerable spots in an organisation’s existing processes and structure. At this stage, it is critical to have a deep dive into business processes and financial statements to discover where fraud risks may arise. 

After the assessment, it is feasible to develop clear fraud detection and prevention policies and procedures. This may encompass developing a code of ethics, control tools and robust processes designed to report potential irregularities.

Further, it is important to conduct dedicated training for employees to raise their awareness of fraud risks and their role in maintaining a high level of ethics within an organisation. It is also recommended to establish the fraud monitoring and regular review systems enabling to follow up on the effectiveness of the measures taken and to make timely adjustments. 

  • Communication and engagement
    • Ensure top management buy-in and commitment. Their support will legitimise the initiative and facilitate organisation-wide compliance. 
    • Communicate the purpose of the fraud risk management system to all employees having defined their roles and responsibilities within the system. 
  • Integration in organisational practices
    • Integrate the fraud risk management policies in daily business activities and culture of an organisation so that fraud prevention becomes a natural part of routine activities.
    • Include compliance with fraud management practices in performance evaluation processes and reward systems to encourage active involvement.
  • Training and awareness raising programmes
    • Conduct comprehensive initial training of employees to explain the new system.  Emphasise its importance and operational principles.
    • Plan regular training programmes to update knowledge and to inform about changes or new fraud risks.
  • Staged implementation
    • Start with a pilot project in one department or structural division of your organisation to assess the effectiveness of controls. Make adjustments before the full-scale implementation.
    • Implement the system in stages by expanding it when each stage demonstrates success and sustainability. This allows making manageable settings and improvements.
  • Implementation of anti-fraud technologies
    • Implement technologies supporting fraud detection and prevention. These may include specialised software, analytical tools or automated whistleblowing systems. 
    • Ensure integration of technologies with the existing systems to achieve the highest level of effectiveness and efficiency.
  • Monitoring and adjustment 
    • Maintain ongoing control over system performance through audits and anti-fraud checks by tracing fraud cases and situations closely related to them. 
    • Promote employee feedback on the system functionality and difficulties encountered by them. 
    • Perform regular system reviews for compliance with all applicable laws and regulations — both local and international ones — particularly if your business operates across different jurisdictions. 
    • Adjust policies, controls and training programmes based on new insights, regulatory updates and changes in the organisation environment or in response to attempted or successful fraudulent activities. 
  • Supportive culture
    • Promote a fraud zero tolerance culture within an organisation. Emphasise the importance of the ethical behaviour and potential consequences of fraudulent activities. 
    • Create and maintain a secure whistleblowing channel to report suspicious activities. Uphold whistleblowers’ rights and protection. 

We help companies implement fraud risk management systems through an analysis of business processes, development of preventive policies, training of employees and implementation of monitoring systems to assess and correct measures.

{{filterContent.facetedTitle}}

Follow us

Required fields are marked with an asterisk(*)

By submitting your email address, you acknowledge that you have read the Privacy Statement and that you consent to our processing data in accordance with the Privacy Statement (including international transfers). If you change your mind at any time about wishing to receive the information from us, you can send us an email message using the Contact Us page.

Hide