Skip to content

The ACFE Fraud Tree and Occupational Fraud Classification

The ACFE Occupational Fraud and Abuse Classification System, known as the Fraud Tree, organises occupational fraud into three primary branches: asset misappropriation, corruption, and financial statement fraud. This topic covers the taxonomy's structure, how investigators use it to frame an engagement, and the frequency and loss data from the ACFE's biennial Report to the Nations.

Last updated:

Share

The ACFE Occupational Fraud and Abuse Classification System, universally called the Fraud Tree, is a hierarchical taxonomy that classifies every known type of occupational fraud under three primary branches: asset misappropriation, corruption, and financial statement fraud. Developed by Joseph T. Wells and adopted by the Association of Certified Fraud Examiners (ACFE) in the early 1990s, the Fraud Tree has become the global reference framework for both fraud prevention program design and fraud examination engagement planning. Each branch subdivides into categories and then into specific scheme types, giving practitioners a precise vocabulary and a structured hypothesis set for any investigation.

The ACFE publishes the Report to the Nations on Occupational Fraud and Abuse every two years, drawing on thousands of cases submitted by Certified Fraud Examiners worldwide. The report quantifies each branch's relative frequency and median loss, tracks how schemes are detected, and maps losses across industry, organisation size, and geography. The data spans cases from the United States, India, the United Kingdom, the European Union, sub-Saharan Africa, and Latin America, making it a genuinely global dataset rather than a single-jurisdiction study.

For a fraud examiner, the Fraud Tree serves two purposes. First, it translates vague suspicion into a testable hypothesis: once the examiner identifies which branch the suspected scheme falls under, the evidence-gathering strategy follows logically. Second, it provides a defensible structure for the fraud risk assessment that organisations run under frameworks such as the Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control framework, the UK Corporate Governance Code, and the Institute of Chartered Accountants of India (ICAI) guidance on fraud risk management.

By the end of this topic you will be able to:

  • Identify the three primary branches of the ACFE Fraud Tree and give two specific scheme examples from each branch.
  • Explain how the Report to the Nations statistics on frequency, median loss, and detection method inform an examiner's initial hypothesis and risk priorities.
  • Distinguish skimming from larceny, and bribery from a conflict of interest, using the Fraud Tree's own definitions.
  • Describe how the Fraud Tree branch relevant to a set of predication facts determines the evidence-gathering approach in a fraud examination.
  • Recognise the red flags associated with billing schemes, payroll fraud, and financial statement fraud, and match each to a specific Fraud Tree subcategory.
Key terms
Occupational fraud
The ACFE defines occupational fraud as the use of one's occupation for personal enrichment through the deliberate misuse or misapplication of the employing organisation's resources or assets. The definition limits scope to fraud committed by insiders, which distinguishes it from external fraud such as identity theft or vendor-side deception that the organisation does not enable.
Asset misappropriation
The largest Fraud Tree branch, covering schemes in which an employee steals or misuses the organisation's assets. Subcategories include cash schemes (skimming, larceny, fraudulent disbursements) and non-cash schemes (misuse of inventory, theft of intellectual property, payroll fraud). Asset misappropriation accounts for the majority of occupational fraud cases by frequency.
Corruption
Schemes in which an employee misuses their position to gain a direct or indirect benefit, typically involving a third party. The four main subcategories in the Fraud Tree are bribery, illegal gratuities, conflicts of interest, and economic extortion. Unlike asset misappropriation, corruption often leaves few accounting traces, making it harder to detect through financial review alone.
Financial statement fraud
Intentional misstatement or omission in financial reports to deceive users of those reports, typically to inflate earnings, understate liabilities, or maintain a credit rating. The rarest Fraud Tree branch by frequency but the highest in median loss, often by an order of magnitude compared to the other branches.
Skimming
An off-book cash theft: revenue is stolen before it enters the accounting system, so no entry is ever made. Skimming is harder to detect because there is no accounting discrepancy to find; detection usually relies on physical controls, surveillance, or tip-offs rather than records review.
Report to the Nations
The ACFE's biennial global study of occupational fraud, compiled from cases submitted by Certified Fraud Examiners. Each edition analyses thousands of real fraud cases across industries and geographies, reporting frequency, median loss, detection method, perpetrator profile, and the impact of anti-fraud controls. The 2024 edition covered cases from 138 countries.

Structure of the ACFE Fraud Tree

The Fraud Tree has three levels. At the top sits the single category of occupational fraud and abuse. Below that are the three primary branches. Each branch then subdivides into categories, and each category into specific scheme types. The full taxonomy contains more than 50 named scheme types. The value of the hierarchy is precision: rather than describing an investigation as being about 'fraud', an examiner can specify that it concerns a billing scheme under fraudulent disbursements, which is itself under cash theft, which is itself under asset misappropriation.

BranchTypical frequency (ACFE data)Typical median lossPrimary detection method
Asset misappropriationHighest (~85-90% of cases)Lowest (~$120,000 per case)Tips, internal audit
CorruptionMid-range (~38-45% of cases)Mid-range (~$200,000 per case)Tips, internal audit
Financial statement fraudLowest (~5-10% of cases)Highest (~$766,000 per case)Internal audit, management review

The frequency-loss inversion is one of the most practically important patterns in the data. Asset misappropriation cases are common but individually bounded; a payroll fraudster can only steal so much before controls or colleagues notice. Financial statement fraud cases are rare but catastrophic: they often involve senior management, run for years, and affect investors, creditors, and counterparties far beyond the organisation itself. Enron, WorldCom in the United States, Wirecard in Germany, and Satyam Computer Services in India all involved financial statement fraud at scale, with losses measured in billions rather than thousands.

Asset misappropriation: cash and non-cash schemes

Asset misappropriation divides into cash schemes and non-cash schemes. Cash schemes are the more thoroughly documented because they leave accounting traces. They fall into three sub-categories: skimming (off-book theft before recording), cash larceny (on-book theft after recording), and fraudulent disbursements (manipulating the payment process to divert funds).

Fraudulent disbursements include five scheme types that appear repeatedly in the Report to the Nations data. Billing schemes involve submitting fictitious or inflated invoices, usually through a shell company controlled by the employee. Payroll fraud includes ghost employees, falsified hours, and commission manipulation. Expense reimbursement schemes inflate or fabricate business expenses. Check and payment tampering covers forged authorisations, altered payee fields, and unauthorised electronic transfers. Register disbursements include false refunds and voided sales that redirect cash to the employee.

Non-cash schemes involve theft or misuse of inventory, equipment, proprietary data, or intellectual property. Though they appear less often in fraud examination case files, the ACFE data shows they are systematically under-reported: non-cash thefts are harder to quantify, harder to attribute to a specific individual, and often written off as shrinkage rather than investigated as fraud. In manufacturing sectors, inventory theft can represent the single largest category of occupational loss.

Corruption schemes: bribery, conflicts of interest, and economic extortion

Corruption schemes, as the Fraud Tree defines them, involve an employee who misuses their organisational influence or authority to benefit themselves or a third party, usually at the organisation's expense. The four subcategories are bribery, illegal gratuities, conflicts of interest, and economic extortion.

Bribery is the offering, paying, soliciting, or receiving of anything of value to influence a business decision. The distinction between bribery and an illegal gratuity turns on timing and intent: a bribe is paid before the favourable decision as an inducement, while an illegal gratuity is paid after the fact as a reward. In practice the distinction matters for criminal prosecution under statutes such as the US Foreign Corrupt Practices Act 1977, the UK Bribery Act 2010, India's Prevention of Corruption Act 1988 (amended 2018), or the OECD Anti-Bribery Convention.

A conflict of interest arises when an employee has an undisclosed personal or financial interest in a transaction that they influence on behalf of the organisation. The employee may not receive cash directly from the vendor; the benefit may be a family relationship, a minority equity stake, or preferential treatment for a connected business. Conflicts of interest are among the hardest corruption schemes to detect because the vendor's invoices and the organisation's payments may both be legitimate on their face. Relationship mapping, vendor database screening, and employee disclosure review are the primary detection tools.

Economic extortion is the mirror image of bribery from the employee's perspective: the employee demands payment from a vendor or counterparty in exchange for a favourable decision, threatening adverse action if the payment is not made. Extortion victims often do not report the scheme because reporting exposes their own payment, which may itself constitute bribery under local law.

Financial statement fraud: schemes and indicators

Financial statement fraud involves intentional manipulation of the financial statements to mislead users, whether investors, creditors, regulators, or the board. The Fraud Tree identifies two directions: overstating assets or revenues (the more common direction, used to inflate apparent profitability or net worth) and understating liabilities or expenses (used to reduce apparent obligations or improve ratios).

Specific scheme types include fictitious revenues, timing differences (recording revenue in an earlier period than earned, or expenses in a later period), concealed liabilities, improper asset valuations, and disclosure fraud (omitting or misrepresenting material information in notes or management commentary). The WorldCom fraud centred on capitalising operating expenses as assets to inflate earnings before interest and tax. Satyam's fraud involved overstating cash balances on the balance sheet over multiple years. Wirecard fabricated entire revenue streams and bank balances across multiple jurisdictions.

The examiner's analytical toolkit for financial statement fraud includes ratio analysis over time and against industry peers, Beneish M-Score and Altman Z-Score models, Benford's Law testing of transaction-level data, and detailed vouching of revenue transactions to supporting contracts and delivery evidence. The audit standards and fraud detection responsibility framework defines what the statutory auditor's obligation is versus what the forensic examiner adds.

Report to the Nations: frequency, loss, and detection data

The Report to the Nations is the most comprehensive longitudinal dataset on occupational fraud available. Each edition draws on cases submitted by Certified Fraud Examiners globally. The 2024 edition covered 1,921 cases from 138 countries with a total loss exceeding $3.1 billion. Because the dataset reflects cases that were detected and investigated, it likely understates true fraud frequency and total organisational loss.

Tips are consistently the leading initial detection method, accounting for roughly 43 percent of cases in recent editions. Of those tips, the majority come from employees, though customers, vendors, and anonymous sources also contribute. The practical implication is direct: organisations with a functioning confidential reporting mechanism (a hotline, an ethics portal, or a third-party reporting service) detect fraud earlier and at lower median loss than those without one. The ACFE data shows that median loss in organisations with a hotline is roughly half that in organisations without one.

Perpetrator profile data consistently shows that fraud loss correlates strongly with the perpetrator's position in the organisation hierarchy. Owner-operator and executive-level frauds have median losses several times higher than employee-level frauds, reflecting both access to larger assets and ability to override controls. Fraud duration before detection averages 12 to 18 months across the full dataset, and duration correlates directly with total loss: every month of an undetected scheme is a month of additional extraction.

The report also tracks the effectiveness of anti-fraud controls. Organisations that have adopted proactive controls, including data analytics, surprise audits, job rotation, and mandatory holiday policies, consistently show lower median fraud losses than those relying solely on traditional internal audit cycles. These findings align with guidance from the Institute of Internal Auditors (IIA) and ICAI, as well as the Financial Reporting Council (FRC) in the UK and the Public Company Accounting Oversight Board (PCAOB) in the US.

Using the Fraud Tree in an examination engagement

The Fraud Tree's practical value in an engagement is to convert a vague allegation into a structured hypothesis and then into a specific evidence-gathering plan. The process begins at predication: the examiner reviews the triggering facts and identifies which Fraud Tree branch or branches are consistent with those facts. This initial classification is a hypothesis, not a conclusion, but it is a testable one.

If predication points to cash disbursement irregularities, the examiner follows the billing scheme pathway: obtain and analyse the vendor master file, identify vendors with PO box addresses and no physical presence, pull invoice-level transaction data, map approver relationships, and search public databases for connections between approvers and vendor registrations. If predication points to unexplained vendor preference or anomalous contract awards, the corruption pathway calls for relationship mapping, gift and hospitality register review, and interview planning targeting both the suspected employee and vendors. If predication involves unexpectedly positive financial results that contradict operational indicators, the financial statement fraud pathway triggers ratio analysis, journal entry testing, and revenue recognition vouching.

The Fraud Tree also guides how the examiner scopes the work and communicates with the client. A clearly defined Fraud Tree hypothesis lets the examiner tell the engagement sponsor: here is the specific type of scheme we are testing for, here is the evidence we need, and here are the controls whose failure this scheme exploits. That precision is more useful to both the legal team and the remediation team than an open-ended mandate to 'look for fraud'. For evidence-gathering methods aligned to each branch, see Evidence Gathering Methods in Fraud Examinations.

Check your understanding
Question 1 of 4· 0 answered

Which Fraud Tree branch has the highest frequency of reported cases but the lowest median loss per case?

Key Takeaways

  • The ACFE Fraud Tree classifies all occupational fraud under three branches: asset misappropriation (most frequent, lowest median loss), corruption (mid-range on both measures), and financial statement fraud (rarest, highest median loss). The frequency-loss inversion is one of the most practically important patterns in fraud risk management.
  • Asset misappropriation subdivides into cash schemes (skimming, larceny, and fraudulent disbursements including billing schemes, payroll fraud, and expense schemes) and non-cash schemes. Skimming is off-book and invisible to reconciliation; its detection depends on physical controls and tip-offs rather than records review.
  • Corruption schemes, including bribery, illegal gratuities, conflicts of interest, and economic extortion, often leave minimal accounting traces. Detection relies on relationship mapping, vendor screening, and employee disclosure review rather than transaction analysis alone.
  • The ACFE Report to the Nations consistently shows that tips are the primary detection mechanism for occupational fraud, that median fraud duration is 12 to 18 months before detection, and that organisations with functioning hotlines detect fraud at roughly half the median loss of those without.
  • In a fraud examination engagement, the Fraud Tree converts predication facts into a testable hypothesis. The branch identified dictates the evidence-gathering strategy, the scope of data requests, and the interview plan, giving the engagement a defensible structure from the first day.
What are the three main branches of the ACFE Fraud Tree?
The ACFE Occupational Fraud and Abuse Classification System divides occupational fraud into three branches: asset misappropriation (theft of cash or non-cash assets), corruption (bribery, conflicts of interest, and illegal gratuities), and financial statement fraud (deliberate misstatement or omission on financial reports). Asset misappropriation is by far the most frequent but carries the lowest median loss; financial statement fraud is the rarest but inflicts the highest median loss.
What does the ACFE Report to the Nations say about how fraud is most often detected?
Across all editions of the Report to the Nations, tips from employees, customers, vendors, and others consistently rank as the most common initial detection method, accounting for roughly 40 to 45 percent of cases. Internal audits and management review follow. Fewer than 5 percent of occupational frauds are first detected by external auditors, which reflects the inherent limitations of a financial-statement audit in detecting concealed occupational schemes.
How long does a typical occupational fraud scheme last before detection?
The ACFE Report to the Nations consistently shows a median duration of 12 to 18 months from the start of a scheme to its detection. Longer-running schemes tend to produce larger total losses because the perpetrator has more time to extract value and cover tracks. This is why early detection controls, particularly hotlines and regular internal audits, have measurable impact on total loss reduction.
What is the difference between skimming and larceny in the ACFE Fraud Tree?
Both are cash asset-misappropriation schemes, but they differ in timing. Skimming is off-book theft: cash is stolen before it is recorded in the accounting system, leaving no trail in the books. Larceny is on-book theft: cash that has already been recorded is stolen after the fact. Because larceny involves funds that appear in the records, it leaves an accounting discrepancy and is generally easier to detect through reconciliation.
How does the ACFE Fraud Tree help structure a fraud examination engagement?
The Fraud Tree gives the examiner a structured hypothesis space. When predication points to a potential irregularity, the examiner identifies which branch or branches are most consistent with the indicators observed. That branch then dictates the evidence-gathering approach: cash schemes call for vouching and bank reconciliations; corruption investigations require contract analysis and relationship mapping; financial statement fraud requires analytical procedures and ratio analysis across reporting periods. The taxonomy prevents the examiner from pursuing an unfocused, open-ended investigation.

Test yourself on Forensic Auditing and Fraud Examination with free, timed mocks.

Practice Forensic Auditing and Fraud Examination questions

Found this useful? Pass it along.

Share

Spotted an error in this page? Report a correction or read our editorial standards.

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.