Skip to main content
Fraud Control Checklist for Teams Under 50Fraud Typologies
5 min readFor Fraud Risk Managers

Fraud Control Checklist for Teams Under 50

Small businesses experience fraud more frequently than large organizations and face higher average losses, often due to a lack of formal detection systems. You don't need enterprise software or a dedicated fraud team to build effective controls. What you need is a structured checklist that fits your operational reality.

This checklist provides a framework for identifying fraud risk points in your business, assigning ownership, and validating that controls work. It's designed for businesses with fewer than 50 employees, where one person often wears multiple hats.

Purpose of the Checklist

Use this checklist when building your first formal fraud detection program or auditing existing ad-hoc controls. It covers three fraud categories that hit small businesses hardest: asset misappropriation (inventory, cash, equipment), financial statement manipulation (inflated revenue, hidden expenses), and vendor fraud (fake invoices, kickback schemes).

The checklist focuses on internal controls you can implement without specialized fraud software. It won't catch sophisticated external attacks, but it will close the gaps that make small businesses easy targets.

Prerequisites

Before you start, ensure you have:

  • Access to your financial records for the past 12 months (bank statements, invoices, payroll records)
  • A list of who can authorize what (spending limits, vendor approvals, system access)
  • 30 minutes per week for the person responsible for running validation checks
  • Management buy-in to enforce segregation of duties, even when it's inconvenient

If you're the owner and currently approve all transactions, sign all checks, and reconcile the books yourself, this checklist will require you to delegate some of those tasks. That's the point.

The Checklist

Cash and Payment Controls

  • Dual authorization on payments over $[set threshold]
    Owner: Finance lead
    Two people must approve any payment exceeding your threshold. For a retail business, this might be $500. For a contractor, $2,000. Set it where a single fraudulent transaction would hurt.

  • Bank reconciliation by someone who doesn't process payments
    Owner: Office manager or bookkeeper
    The person who reconciles your bank statement cannot be the same person who enters invoices or initiates transfers. If you're too small for that split, the owner reconciles.

  • Monthly review of all new vendors added to your system
    Owner: Department head or owner
    Review the vendor master file every 30 days. Look for personal email addresses, P.O. boxes in unfamiliar locations, or vendors with names similar to existing suppliers.

  • Surprise cash counts (if you handle physical cash)
    Owner: Manager or owner
    Unannounced counts at irregular intervals. Don't schedule them. Don't warn the person handling the drawer.

Inventory and Asset Controls

  • Physical inventory count every quarter
    Owner: Operations lead
    Compare physical count to system records. Investigate variances over [set percentage, typically 2-5%]. Document the investigation.

  • Asset disposal log with approval requirements
    Owner: Office manager
    Any equipment, vehicle, or asset leaving the premises gets logged with date, recipient, reason, and approver signature. No exceptions for "broken" or "obsolete" items.

  • Access restrictions on storage areas
    Owner: Facilities or operations
    Limit who has keys or access codes to inventory rooms, supply closets, and equipment storage. Review the access list every six months.

Vendor and Procurement Controls

  • Three-way match on invoices over $[threshold]
    Owner: Accounts payable
    Match purchase order, receiving document, and vendor invoice before payment. For service vendors where receiving docs don't apply, require manager sign-off that the service was delivered.

  • Vendor payment details verified at setup
    Owner: Finance or admin
    Before adding a vendor to your payment system, call the company's main number (not the number on the invoice) and verify the bank account details with their accounting department.

  • Quarterly review of duplicate payments
    Owner: Bookkeeper or finance lead
    Run a report of all payments sorted by amount and vendor. Look for exact duplicate amounts paid to the same vendor within 90 days.

Payroll Controls

  • Payroll changes require written authorization
    Owner: HR or owner
    Raises, bonuses, and new hires require a signed form from the department head. Email doesn't count. Keep the forms.

  • Annual verification that employees exist
    Owner: Manager or owner
    Once a year, verify that every person on payroll is actually working for you. For remote workers, schedule a video call. This catches ghost employee schemes.

Access and System Controls

  • Role-Based Access Control enforced in financial systems
    Owner: IT or system admin
    Users can only access the functions they need. Your inventory clerk shouldn't be able to add vendors. Your sales team shouldn't see payroll.

  • Quarterly access review and cleanup
    Owner: IT or owner
    Review who has access to what. Remove access for departed employees within 24 hours of termination. Downgrade access for employees who changed roles.

  • System activity logs reviewed monthly
    Owner: IT or finance lead
    Check logs for after-hours access, failed login attempts, or unusual activity patterns. Most accounting systems generate these automatically.

How to Customize It

Set your thresholds based on what would hurt. If losing $1,000 would disrupt your operations, set dual authorization at $500. If your average invoice is $50, a three-way match on every transaction will bury you in paperwork, so set it at $200 or $300 instead.

Assign owners based on who has the time and the separation from the process. The person who orders supplies shouldn't be the person who receives them or pays for them. If you're too small to fully segregate, add a review step: the owner or a manager spot-checks a sample of transactions monthly.

For controls marked as quarterly or annual, put them on your calendar with specific dates. "Review vendor list quarterly" becomes "Review vendor list on January 15, April 15, July 15, October 15."

If a control doesn't apply to your business, cross it out. If you don't carry inventory, skip those items. If you don't handle cash, ignore the cash controls. But if you skip a control because it seems like too much work, that's exactly where fraud will happen.

Validation Steps

Every 90 days, audit your own checklist:

  1. Pull three transactions at random from the past quarter. Walk them through the relevant controls. Did dual authorization happen? Was the three-way match documented? If controls failed, why?

  2. Test one control by trying to break it. Attempt to add a vendor without approval. Try to process a payment above your threshold with only one signature. If you succeed, the control isn't working.

  3. Review exception logs. Any time someone overrides a control ("we needed to pay this invoice urgently"), it should be logged. Review those exceptions. If you're seeing the same override every week, the control is poorly designed.

  4. Calculate your fraud loss baseline. Track shrinkage, unexplained variances, and write-offs. If these numbers are climbing, your controls aren't deterring fraud, they're just documenting it.

The goal isn't perfection. It's making fraud harder to commit and easier to detect before losses compound. In the US, fraud results in losses of $20 billion each year, and small businesses absorb a disproportionate share because weak controls make them appealing targets. This checklist won't eliminate fraud risk, but it will move you off the easy-target list.

You Might Also Like