Asset Misappropriation and Skimming
The most common category of occupational fraud: employees stealing cash, diverting payments, and misappropriating non-cash assets, and the internal controls that stop or detect each scheme.
Last updated:
Asset misappropriation is the most common category of occupational fraud, present in approximately 86% of cases documented in the ACFE Report to the Nations. It encompasses three main branches: skimming (cash intercepted before recording), cash larceny (cash taken after recording), and fraudulent disbursements (legitimate payment channels exploited to divert funds). Non-cash misappropriation, including inventory theft and proprietary-information theft, completes the taxonomy. Detection depends on matching the control and analytics response to the specific mechanics of each scheme type.
Asset misappropriation is by far the most common form of occupational fraud, appearing in roughly 86% of all cases the ACFE records in its biennial Report to the Nations. It is also, median loss by median loss, the least costly of the three ACFE fraud categories: most asset-misappropriation schemes involve a single employee exploiting a local control weakness rather than an executive-level conspiracy to overstate earnings. But small individual losses aggregate; the ACFE estimates that the typical organisation loses 5% of its annual revenue to fraud, and asset misappropriation schemes are responsible for most of that drain.
The ACFE Fraud Tree divides asset misappropriation into cash schemes and non-cash schemes. Cash schemes divide further into skimming (taking cash before it is recorded), cash larceny (taking cash after it is recorded), and fraudulent disbursements (manipulating the payments process to divert money outward). Non-cash schemes involve stealing inventory, equipment, and proprietary information. Each branch of the tree has its own mechanics and its own control countermeasures.
This topic maps each major scheme type, explains the control environment that enables it, and identifies the detection signals that appear in accounting records, payroll data, and physical observations. The emphasis throughout is on the investigative perspective: what does the scheme look like in the data, and what is the minimum evidence set needed to support a conclusion.
By the end of this topic you will be able to:
- Distinguish skimming from cash larceny by explaining the recording-timeline difference and its implications for detection method.
- Identify the primary sub-types of fraudulent disbursement schemes (billing, payroll, expense reimbursement, register disbursements) and the control weakness each exploits.
- Explain why segregation of duties is the foundational preventive control and describe compensating detective controls for environments where full segregation is impractical.
- Apply data-analytics procedures (duplicate-payment testing, Benford's Law, vendor-employee matching) to a population of payroll or vendor-payment records to surface misappropriation indicators.
- Reconstruct the evidence chain in a ghost-employee investigation from initial tip through quantification of loss.
- Skimming
- Taking cash or other payments before they are entered into the accounting records. Leaves no direct accounting discrepancy, making detection dependent on external evidence such as customer receipts, till surveillance, or comparison to expected revenue.
- Cash larceny
- Taking cash that has already been recorded in the accounting system. The record exists, so the theft creates a provable discrepancy between the book entry and the physical cash, making detection more straightforward than skimming.
- Fraudulent disbursement
- A scheme in which the perpetrator manipulates the organisation's outbound payment process to divert money to themselves or an accomplice. The main sub-types are billing schemes, payroll fraud, expense reimbursement fraud, and register disbursements.
- Ghost employee
- A fictitious or departed person on the payroll whose wages are diverted to the perpetrator. Detection relies on headcount reconciliation, supervisor attestation of active personnel, and physical sign-in verification.
- Lapping
- A scheme to conceal the theft of cash from customer receipts by applying a later customer's payment to the earlier customer's account. Creates a running gap between customer accounts and cash receipts that grows unless the lapper catches up or is discovered.
- Segregation of duties
- The principle that the authorisation, custody, and recording of any transaction should be performed by different people. Its absence is the single most common control weakness enabling asset misappropriation.
Skimming: taking cash before the books see it
Skimming is an off-books fraud: the intercepted cash never appears in the accounting records. A cashier who accepts payment but does not ring the sale, a billing clerk who deposits only part of a cash payment and pockets the rest, and an accounts-receivable employee who intercepts a cheque and destroys the remittance advice are each running a skimming scheme.
Because no entry is ever made, ledger reconciliation cannot reveal the theft. Detection requires evidence outside the books: register tapes compared to cash counts, expected revenue benchmarks compared to recorded revenue, or customer complaints about payments not credited to their accounts.
- Sales skimming: intercepting cash at the point of sale before recording. Detected by surprise cash counts, surveillance, or comparison of physical transaction count to registered sales.
- Receivables skimming: intercepting customer payments before posting to the accounts. Detected by lapping patterns, customer statements, and direct customer confirmation.
- Mail skimming: intercepting cheques or cash from incoming mail before they reach the cashier. Requires access to incoming mail and is usually associated with small organisations lacking mailroom controls.
Fraudulent disbursements: billing and payroll fraud
Fraudulent disbursement schemes direct the organisation's own payment process to send money to the perpetrator or an accomplice. The payment appears in the books as a legitimate expense; the fraud lies in the substance of the transaction, not its form.
Billing schemes are the most common fraudulent disbursement type. The simplest version creates a shell company in the perpetrator's name, registers it in the vendor master file, submits invoices for goods or services never provided, and approves and processes the payment. More sophisticated versions involve real vendors whose invoices are inflated, with the perpetrator receiving a kickback from the vendor.
Payroll fraud takes several forms. Ghost employees are the most studied: a fictitious person or a departed employee whose payroll entry was not terminated continues receiving wages that are diverted to the perpetrator. Commission fraud involves inflating sales figures to generate excess commission payments. Timesheet fraud involves claiming hours not worked. The ACFE data consistently shows payroll schemes have a longer average duration before detection than billing schemes, often running for several years.
| Scheme type | Median duration (ACFE 2022) | Primary detection method |
|---|---|---|
| Billing fraud (shell company) | 18 months | Vendor master analysis: address/phone/bank matches to employees |
| Ghost employee | 18 months | Headcount reconciliation; supervisor attestation of active staff |
| Expense reimbursement fraud | 18 months | Duplicate receipt testing; policy-limit analysis |
| Commission fraud | 24 months | Sales record comparison to commission claims |
| Register disbursement | 12 months | Void and refund transaction analysis |
Non-cash misappropriation
Non-cash misappropriation covers theft of any organisational asset other than cash or monetary instruments. The most common forms are inventory theft and misuse of equipment, vehicles, and physical property. Theft of proprietary information and intellectual property is less visible but increasingly significant.
Inventory theft is typically detected through periodic physical counts compared against book records. The core investigation task is separating genuine theft from breakage, shrinkage, and recording errors, all of which produce discrepancies. Consistent shortfalls concentrated in a specific location, product category, or shift are more indicative of theft than of systemic error.
Internal controls: the prevention and detection framework
Internal controls against asset misappropriation fall into two categories: preventive controls that make a scheme harder to execute, and detective controls that surface it once under way. Both are necessary. Preventive controls can be overridden by colluding employees or management; detective controls applied only annually may allow a scheme to run for a full year before detection.
- Segregation of duties: split the authorise, record, and custody functions. No single person should be able to approve a payment, record it, and reconcile the bank account.
- Physical controls: locked cash drawers, access-controlled inventory areas, fixed-asset tagging, and vehicle tracking.
- Surprise cash counts: unannounced counts compare physical cash to the register balance at random intervals. Predictable counting schedules allow perpetrators to replace stolen cash for the count.
- Independent bank reconciliation: reconciliation performed by someone who did not process payments, with review of original cancelled cheques or bank images rather than the company's own records.
- Vendor master controls: approval process for adding new vendors; periodic comparison of vendor addresses, telephone numbers, and bank accounts against employee data.
- Payroll controls: independent headcount verification; mandatory holiday policies (many payment schemes require the perpetrator to be present to maintain the fraud); direct deposit to verified employee accounts.
The ACFE data consistently shows that organisations with fewer controls have higher median fraud losses and longer fraud durations. The cost of basic preventive controls, particularly segregation of duties in small finance teams, is frequently cited as a barrier in small and medium organisations, but the cost of a single undetected fraud typically exceeds the annual cost of the control many times over.
Data analytics for detection
Data analytics is the primary detection tool in large organisations because it can examine an entire transaction population. Manual review of a representative sample may miss a scheme that affects only a small percentage of payments.
- Duplicate payment testing: matching invoice number, vendor, and amount across all payment records to find duplicate submissions.
- Round-number testing: filtering for payments ending in .00 or .50, which human-created fictitious invoices favour over the irregular amounts of genuine commerce.
- Vendor-employee match: comparing vendor master addresses, phone numbers, tax IDs, and bank accounts against employee records to find shell companies in employees' names.
- Benford's Law on expense claims: first-digit analysis of expense claim amounts. Human-chosen numbers below a reimbursement threshold (such as $25) cluster unnaturally because the perpetrator chooses amounts to stay under approval limits.
- Sequence gaps and duplicates: invoice sequence gaps suggest missing invoices; duplicate sequences suggest fabricated ones.
Why is skimming harder to detect from accounting records alone than cash larceny?
Key Takeaways
- Skimming takes cash before it enters the books, leaving no ledger discrepancy; detection requires external evidence such as customer confirmations, surveillance, or expected-versus-actual revenue analysis.
- Fraudulent disbursements, particularly billing fraud and ghost-employee payroll schemes, exploit organisations where the same person can add vendors or employees, initiate payments, and reconcile accounts.
- Segregation of duties is the foundational preventive control; when it cannot be fully implemented in a small team, compensating detective controls such as surprise counts and independent reconciliation become essential.
- Data analytics applied to the full population of payroll and vendor-payment records routinely detects schemes that sample-based testing misses: duplicate payments, round-number clustering, and vendor-employee address matches.
- Asset misappropriation is the most common occupational fraud category by frequency and the one most directly controlled by basic preventive measures, making the cost-benefit case for those controls straightforward.
What is the difference between skimming and cash larceny?
What is a ghost employee?
What is the most common type of occupational fraud by frequency?
How does billing fraud work?
What internal control most effectively prevents asset misappropriation?
Test yourself on Forensic Accounting and Financial Forensics with free, timed mocks.
Practice Forensic Accounting and Financial Forensics questionsSpotted an error in this page? Report a correction or read our editorial standards.