The Fraud Triangle and Cressey's Model
Donald Cressey's three-element model of occupational fraud, pressure, opportunity, and rationalization, emerged from empirical research in the 1950s and remains the central conceptual tool for understanding why trusted employees commit fraud.
Last updated:
The fraud triangle is a three-element model developed by criminologist Donald Cressey from interviews with 133 convicted embezzlers in the late 1940s. It holds that occupational fraud occurs when three conditions converge: a financial pressure the person believes they cannot disclose to others, an opportunity created by weaknesses in the control environment, and a rationalization that allows the person to act dishonestly while preserving a self-image of basic honesty. Remove any one element and, according to Cressey's model, the fraud does not occur. A 2004 extension by Wolfe and Hermanson added a fourth element, capability, addressing why only some individuals who face all three conditions actually commit the act.
In the late 1940s, criminologist Donald Cressey interviewed convicted embezzlers at three American prisons to find what every case had in common. The pattern he identified across 133 subjects became the foundational model in occupational fraud investigation.
The fraud triangle holds that every case of occupational fraud involves three elements appearing together: a financial pressure the person felt they could not share with others, an opportunity in the control environment that made the theft look feasible, and a rationalization that let the person frame what they were doing as something other than dishonesty. Remove any one element and the fraud, at least according to Cressey, does not happen. Change the opportunity and you change the risk.
This topic reconstructs Cressey's original research, explains each element in depth, describes the fraud diamond extension that added capability as a fourth factor, and shows how investigators apply the model in practice: to assess risk, to direct interview questions, and to explain why a trusted employee became a fraudster. The model is not a prediction machine. It is a framework for structured thinking about motivation and control.
By the end of this topic you will be able to:
- Identify the three elements of Cressey's fraud triangle and explain the specific role each plays in enabling occupational fraud.
- Distinguish between personal and organisational forms of financial pressure and explain why non-shareability is the critical characteristic.
- Describe the fraud diamond extension and explain what capability adds to the original three-condition model.
- Apply the fraud triangle framework to a fraud risk assessment, mapping each element to corresponding control responses and interview strategies.
- Recognise the limits of the model: its origin in occupational fraud, its descriptive rather than predictive character, and where it requires adaptation for financial-statement fraud cases.
- Occupational fraud
- The use of one's occupation for personal enrichment through the deliberate misuse or misapplication of the employing organisation's resources or assets. Cressey's model was built specifically for this category.
- Non-shareable financial problem
- Cressey's original phrase for what is now called pressure or incentive. The problem is non-shareable because the person believes they cannot disclose it without damaging their reputation, relationships, or position.
- Rationalization
- The internal justification that allows a person to commit fraud while maintaining a self-image as an honest individual. Common forms include 'I was only borrowing it', 'I was underpaid anyway', or 'the company can afford it'.
- Fraud diamond
- The four-element extension of the fraud triangle proposed by Wolfe and Hermanson (2004), adding capability to pressure, opportunity, and rationalization. Capability focuses on the specific skills and access needed to execute and conceal a particular fraud.
- Control environment
- The set of organisational policies, procedures, and cultural attitudes that collectively determine how much opportunity a fraudster has. Weak controls, missing segregation of duties, and absent oversight directly create opportunity.
- Management override
- The capacity of senior management to circumvent controls they themselves designed or approved, a particularly dangerous form of opportunity that audit and detective controls often fail to catch.
Cressey's research: how the model was built
Donald Cressey completed his doctoral research at Indiana University under sociologist Edwin Sutherland, whose differential association theory had already challenged simple explanations of criminal behaviour. Cressey's own question was more focused: why do people who occupy positions of trust, who have been given legitimate access to other people's money, cross the line and take it?
He interviewed 133 inmates at Joliet and Menard Correctional Centers in Illinois and Terre Haute Federal Prison in Indiana, all convicted of embezzlement. The interviews were open-ended and exploratory, not structured questionnaires, and Cressey was looking for patterns in the subjects' own accounts of their behaviour. His methodology would not satisfy modern standards for grounded theory research, but it was unusually direct: he was asking fraudsters themselves to explain what happened.
The pattern that emerged was remarkably consistent. Cressey found that every case involved a financial problem the person believed they could not share with others, access to the money or assets as a direct result of their trusted position, and a way of thinking about what they were doing that made it seem acceptable, at least temporarily. He published his findings as Other People's Money: A Study in the Social Psychology of Embezzlement in 1953.
Opportunity: control weakness as the enabling condition
Opportunity is the element that internal controls directly address. The fraudster needs not just the access to commit the fraud but also a realistic belief that they can conceal it. A poorly designed payroll system that allows one person to add ghost employees, approve the payroll, and receive the corresponding bank transfers without any independent review creates exactly this opportunity. A well-designed system requiring multiple approvals and automatic reconciliation makes the same fraud far harder to execute and conceal.
The three most common opportunity conditions identified in the ACFE's research across its biennial Reports to the Nations are: lack of internal controls (cited in the largest share of cases), override of existing controls, and lack of management review. These are not exotic vulnerabilities. They are the ordinary failures of understaffed, overconfident, or complacent organisations.
Rationalization: the honest dishonest person
Rationalization is the element with the most direct relevance to investigative interviews. Cressey found that his subjects uniformly adopted mental framings that allowed them to act dishonestly while preserving a self-image of basic honesty. These were not rationalizations invented after the fact to explain their actions to the researcher; Cressey concluded they were present at the time of the act, functioning as a necessary psychological precondition.
- 'I was only borrowing it': the person intends to repay and frames the act as a temporary loan rather than permanent theft. The repayment rarely materialises, and the framing is abandoned or adjusted as the fraud continues.
- 'I am underpaid and deserve this': the fraud is framed as a salary correction or compensation for perceived mistreatment, making it feel like justice rather than theft.
- 'The company can afford it' or 'nobody is really hurt': dehumanising the victim by treating them as an institution large enough to absorb the loss without real consequence.
- 'Everyone does it': normalising the behaviour by perceiving it as widespread, even when there is no evidence for that belief.
In an interview, rationalization often surfaces when a subject is asked open-ended questions about their role and their relationship with the organisation. Statements about being undervalued, about management hypocrisy, or about the organisation's financial capacity are often rationalizations in motion. A skilled interviewer recognises them as such and uses them to structure follow-up questions. The PEACE model interview framework (Preparation, Engage/Explain, Account, Closure, Evaluate) is particularly effective at drawing out this kind of account.
The fraud diamond: adding capability
In a 2004 article in the CPA Journal, David Wolfe and Dana Hermanson proposed a fourth element: capability. Pressure, opportunity, and rationalization describe the conditions for fraud, but do not explain why, in an organisation where many employees face the same conditions, only one or a few actually act. Capability, they argued, is the difference: the specific combination of position, skills, and personal traits that allows a particular individual to execute and conceal a particular fraud.
The capability element has several components. Position matters because not every employee with motivation and rationalisation has the access to commit the specific fraud that would satisfy their need. Skills matter because complex financial-statement fraud requires accounting knowledge; a complex cyber-enabled fraud requires technical skills. Personal traits such as confidence, tolerance for risk, and the ability to maintain a convincing narrative under scrutiny all contribute to whether a person who meets the first three conditions will actually act.
In practice, the fraud diamond redirects the investigator's attention toward the specific individuals who were in a position to commit the detected fraud type. It is not enough to know that the billing department had weak controls (opportunity). The question becomes: of the people in that department, who had the accounting knowledge to construct the false invoices, the system access to approve them, and the seniority to avoid scrutiny?
Applying the model in fraud risk assessment and investigation
Fraud risk assessment, as required by auditing standards (ISA 240, AU-C Section 240) and internal audit standards, uses Cressey's elements as a structuring framework. The risk assessment asks: where are the significant pressures in this organisation? Where are the opportunity gaps in the control framework? What signals are there about rationalising attitudes in the culture? The answers direct attention to the highest-risk areas without requiring specific allegations.
| Model element | Risk-assessment questions | Investigation application |
|---|---|---|
| Pressure | Which roles or individuals face unachievable targets, financial distress, or debt? | Interview focuses on financial circumstances, lifestyle, and recent stresses |
| Opportunity | Where are segregation of duties absent? Where does management override exist? | Transaction testing targets periods of weakest control; IT access logs reviewed |
| Rationalization | What is the cultural attitude toward expense claims, policy compliance, and reporting? | Interview uses open-ended questions to draw out self-justifying language |
| Capability (diamond) | Who in the identified risk area has the skills and access to commit this specific fraud type? | Narrows the suspect population by position, access rights, and relevant expertise |
One practical caution: the model was built for occupational fraud (individual employees stealing from their employer). It applies less cleanly to management fraud or financial-statement fraud perpetrated by senior executives, where the pressure is often corporate rather than personal and the rationalization is often collective ('we are managing earnings, not committing fraud'). Investigators working on complex financial-statement cases use the triangle as a starting framework and then adapt it to the organisational dynamics of the specific case.
Cressey described the first element of his model as a 'non-shareable financial problem'. Why is the word 'non-shareable' significant?
Key Takeaways
- Donald Cressey built the fraud triangle from interviews with 133 convicted embezzlers, making it an empirically grounded model of occupational fraud motivation rather than a theoretical construct.
- The three elements are pressure (a non-shareable financial problem), opportunity (a control environment that makes the fraud feasible and concealable), and rationalization (an internal justification that preserves the person's self-image as honest).
- The fraud diamond (Wolfe and Hermanson, 2004) adds a fourth element, capability, directing attention to who specifically had the position and skills to execute the particular fraud type.
- In practice, the model is used in fraud risk assessment to identify high-risk areas, in investigation to structure interviews and direct transaction testing, and in reporting to explain why a trusted employee committed the fraud.
- The triangle describes conditions associated with fraud, not a prediction of individual behaviour; it guides where to look, but does not generate probabilities.
What are the three elements of the fraud triangle?
Where did Cressey's model come from?
What is the fraud diamond and how does it extend Cressey's model?
Can the fraud triangle be used in a live investigation?
Test yourself on Forensic Accounting and Financial Forensics with free, timed mocks.
Practice Forensic Accounting and Financial Forensics questionsSpotted an error in this page? Report a correction or read our editorial standards.