The challenge isn't that your organization lacks controls. You've got authorization workflows, segregation of duties, and reconciliation procedures. The real problem? You don't know which controls actually address your fraud risks and which ones just make you feel protected.
A fraud risk management team recently faced this exact gap. They'd documented dozens of controls across purchasing, sales, and IT operations. But when asked to show which controls prevented vendor invoice fraud versus which ones caught it after the fact, they couldn't answer. Their control documentation existed in policy manuals and process flowcharts, but it wasn't mapped to specific fraud scenarios. When an employee exploited the purchasing process by creating fictitious vendors, the team discovered their authorization controls only applied to purchase amounts, not vendor setup.
The Environment
This scenario plays out across organizations that treat control documentation as a compliance checkbox rather than an operational defense layer. The team operated in an environment where:
- Multiple departments maintained separate control inventories.
- Process-specific controls (sales authorization, purchase limits) existed alongside general IT controls.
- No single view showed which fraud risks had preventive coverage versus detective coverage.
- The Fraud Triangle's three drivers (motivation, opportunity, rationalization) weren't explicitly mapped to control responses.
According to Stoy Hayward's FraudTrack survey, greed accounted for 63 percent of fraud cases in 2007 where a cause was cited. That motivation hasn't disappeared. What's changed is the sophistication of how employees exploit control gaps.
Control Mapping as Risk Translation
The team implemented a structured control mapping process that moved beyond documentation to risk correlation:
Step 1: Differentiate control types
They separated preventive controls (designed to stop fraud before it occurs) from detective controls (designed to catch it afterward). This distinction matters because you need both, but in different proportions depending on the risk.
For purchasing, preventive controls included authorization limits requiring manager approval above certain thresholds. Detective controls included monthly reconciliation of vendor master files against payment records.
Step 2: Separate general from process-specific controls
General controls support the entire organization (IT access management, network security). Process-specific controls live inside individual workflows. The sales system required all transactions to be recorded immediately to prevent revenue manipulation. The purchase process embedded authorization limits to prevent unauthorized spending.
They documented each control type in department-specific policies and procedures, creating a reference framework employees could actually use.
Step 3: Map controls to identified fraud risks
This is where most teams stop short. The team took each fraud risk from their assessment and asked: "Which specific controls address this risk? Are they preventive or detective? Are there gaps?"
For the risk of employees misusing the purchase process, they mapped it to authorization controls. But the mapping revealed a weakness: authorization limits existed for purchase amounts but not for vendor creation. An employee could add a shell company to the vendor master file without approval, then submit invoices under the authorization threshold.
Step 4: Identify and remediate weak controls
The purchasing department designed new authorization requirements for vendor setup, requiring departmental head approval and validation against external business registries. This preventive control closed the gap before the next fraudulent vendor could be created.
Results
The control mapping process produced measurable improvements:
- The team identified specific control gaps in purchasing, sales recording, and IT access management.
- They redesigned authorization controls to cover vendor setup, not just purchase amounts.
- Department heads could now see which fraud risks lacked adequate preventive controls.
- The organization shifted from reactive fraud detection to proactive prevention in high-risk processes.
More importantly, they built a framework for ongoing control assessment. When new fraud risks emerge (synthetic identity schemes, payment diversion attacks), they can quickly identify whether existing controls provide coverage or whether new controls are needed.
What They'd Do Differently
Looking back, the team identified three areas they'd approach differently:
Start with high-impact processes: They initially tried to map controls across all departments simultaneously. A better approach: focus first on processes with direct financial impact (purchasing, payments, revenue recognition), then expand to supporting functions.
Involve process owners earlier: Control mapping works best when the people running the process help identify gaps. The team initially treated this as a compliance exercise led by the fraud risk function. Bringing in purchasing managers and sales operations earlier would have surfaced practical control weaknesses faster.
Build the Fraud Triangle into the mapping template: They eventually correlated controls to motivation, opportunity, and rationalization, but this should have been part of the initial framework. A control that reduces opportunity (authorization limits) works differently than one that addresses rationalization (clear policies on acceptable behavior, fear of detection).
Takeaways for Your Team
If you're managing fraud risk controls, here's how to move from documentation to effective mapping:
Audit your control inventory by type: Can you quickly list which controls are preventive versus detective? Which are general versus process-specific? If not, your documentation isn't operationally useful.
Map to fraud scenarios, not just risks: Don't just say "purchasing fraud is a risk." Describe the specific fraud scenario (employee creates shell vendor, submits invoices under approval threshold, receives payments). Then identify which controls prevent it and which detect it.
Look for authorization gaps: Authorization controls are common, but they often cover amounts, not setup. Review whether your authorization workflows extend to master file changes (vendor creation, customer setup, user provisioning).
Document in a usable format: Policies and procedures are necessary, but your fraud risk team needs a matrix showing Risk → Control → Type → Owner. When a new fraud typology emerges, you need to see coverage gaps in minutes, not days.
Test the mapping under pressure: Run a tabletop exercise where you simulate a fraud scenario. Can your team quickly identify which controls should have prevented it? Which should have detected it? If there's confusion, your mapping isn't clear enough.
Organizations that manage fraud risk effectively don't just have controls. They know exactly which controls address which risks, where the gaps are, and how to close them before the next employee decides that 63 percent statistic applies to them.



