Small businesses experience fraud more frequently than large organizations and face higher average losses, often due to a lack of formal detection systems. You don't need enterprise software or a dedicated fraud team to build effective controls. What you need is a structured checklist that fits your operational reality.
This checklist provides a framework for identifying fraud risk points in your business, assigning ownership, and validating that controls work. It's designed for businesses with fewer than 50 employees, where one person often wears multiple hats.
Purpose of the Checklist
Use this checklist when building your first formal fraud detection program or auditing existing ad-hoc controls. It covers three fraud categories that hit small businesses hardest: asset misappropriation (inventory, cash, equipment), financial statement manipulation (inflated revenue, hidden expenses), and vendor fraud (fake invoices, kickback schemes).
The checklist focuses on internal controls you can implement without specialized fraud software. It won't catch sophisticated external attacks, but it will close the gaps that make small businesses easy targets.
Prerequisites
Before you start, ensure you have:
- Access to your financial records for the past 12 months (bank statements, invoices, payroll records)
- A list of who can authorize what (spending limits, vendor approvals, system access)
- 30 minutes per week for the person responsible for running validation checks
- Management buy-in to enforce segregation of duties, even when it's inconvenient
If you're the owner and currently approve all transactions, sign all checks, and reconcile the books yourself, this checklist will require you to delegate some of those tasks. That's the point.
The Checklist
Cash and Payment Controls
Dual authorization on payments over $[set threshold]
Owner: Finance lead
Two people must approve any payment exceeding your threshold. For a retail business, this might be $500. For a contractor, $2,000. Set it where a single fraudulent transaction would hurt.Bank reconciliation by someone who doesn't process payments
Owner: Office manager or bookkeeper
The person who reconciles your bank statement cannot be the same person who enters invoices or initiates transfers. If you're too small for that split, the owner reconciles.Monthly review of all new vendors added to your system
Owner: Department head or owner
Review the vendor master file every 30 days. Look for personal email addresses, P.O. boxes in unfamiliar locations, or vendors with names similar to existing suppliers.Surprise cash counts (if you handle physical cash)
Owner: Manager or owner
Unannounced counts at irregular intervals. Don't schedule them. Don't warn the person handling the drawer.
Inventory and Asset Controls
Physical inventory count every quarter
Owner: Operations lead
Compare physical count to system records. Investigate variances over [set percentage, typically 2-5%]. Document the investigation.Asset disposal log with approval requirements
Owner: Office manager
Any equipment, vehicle, or asset leaving the premises gets logged with date, recipient, reason, and approver signature. No exceptions for "broken" or "obsolete" items.Access restrictions on storage areas
Owner: Facilities or operations
Limit who has keys or access codes to inventory rooms, supply closets, and equipment storage. Review the access list every six months.
Vendor and Procurement Controls
Three-way match on invoices over $[threshold]
Owner: Accounts payable
Match purchase order, receiving document, and vendor invoice before payment. For service vendors where receiving docs don't apply, require manager sign-off that the service was delivered.Vendor payment details verified at setup
Owner: Finance or admin
Before adding a vendor to your payment system, call the company's main number (not the number on the invoice) and verify the bank account details with their accounting department.Quarterly review of duplicate payments
Owner: Bookkeeper or finance lead
Run a report of all payments sorted by amount and vendor. Look for exact duplicate amounts paid to the same vendor within 90 days.
Payroll Controls
Payroll changes require written authorization
Owner: HR or owner
Raises, bonuses, and new hires require a signed form from the department head. Email doesn't count. Keep the forms.Annual verification that employees exist
Owner: Manager or owner
Once a year, verify that every person on payroll is actually working for you. For remote workers, schedule a video call. This catches ghost employee schemes.
Access and System Controls
Role-Based Access Control enforced in financial systems
Owner: IT or system admin
Users can only access the functions they need. Your inventory clerk shouldn't be able to add vendors. Your sales team shouldn't see payroll.Quarterly access review and cleanup
Owner: IT or owner
Review who has access to what. Remove access for departed employees within 24 hours of termination. Downgrade access for employees who changed roles.System activity logs reviewed monthly
Owner: IT or finance lead
Check logs for after-hours access, failed login attempts, or unusual activity patterns. Most accounting systems generate these automatically.
How to Customize It
Set your thresholds based on what would hurt. If losing $1,000 would disrupt your operations, set dual authorization at $500. If your average invoice is $50, a three-way match on every transaction will bury you in paperwork, so set it at $200 or $300 instead.
Assign owners based on who has the time and the separation from the process. The person who orders supplies shouldn't be the person who receives them or pays for them. If you're too small to fully segregate, add a review step: the owner or a manager spot-checks a sample of transactions monthly.
For controls marked as quarterly or annual, put them on your calendar with specific dates. "Review vendor list quarterly" becomes "Review vendor list on January 15, April 15, July 15, October 15."
If a control doesn't apply to your business, cross it out. If you don't carry inventory, skip those items. If you don't handle cash, ignore the cash controls. But if you skip a control because it seems like too much work, that's exactly where fraud will happen.
Validation Steps
Every 90 days, audit your own checklist:
Pull three transactions at random from the past quarter. Walk them through the relevant controls. Did dual authorization happen? Was the three-way match documented? If controls failed, why?
Test one control by trying to break it. Attempt to add a vendor without approval. Try to process a payment above your threshold with only one signature. If you succeed, the control isn't working.
Review exception logs. Any time someone overrides a control ("we needed to pay this invoice urgently"), it should be logged. Review those exceptions. If you're seeing the same override every week, the control is poorly designed.
Calculate your fraud loss baseline. Track shrinkage, unexplained variances, and write-offs. If these numbers are climbing, your controls aren't deterring fraud, they're just documenting it.
The goal isn't perfection. It's making fraud harder to commit and easier to detect before losses compound. In the US, fraud results in losses of $20 billion each year, and small businesses absorb a disproportionate share because weak controls make them appealing targets. This checklist won't eliminate fraud risk, but it will move you off the easy-target list.



