Fraud Assessment for Small and Medium-Sized Businesses

Written by Robert Nordlander, CPA, CFE | July 30, 2026 at 8:53 PM
Fraud assessments answer two simple questions: where could fraud happen, and what are we doing to stop it? If those questions are ignored (or never asked), an owner may not find out what is going on in their own business until the losses are already painful.

Fraud in a small business rarely starts with an action movie plot. It usually starts with one trusted employee, one weak process, and one transaction nobody questions. By the time the problem is discovered, the money may be gone, and the records may be in a mess.

That is why fraud assessment matters. Smaller businesses do not have layers of accounting staff, internal auditors, compliance departments, and audit committees. They have people wearing multiple hats, informal approvals, and owners who assume trust is the same thing as control. It is not.

A fraud assessment answers a simple question: where could fraud happen, and what are we doing to stop it? If that question is answered honestly, the owner has a clear view of the business’s exposure. If those questions are ignored or never asked, the business may not learn the truth until the loss is already painful.

Why Smaller Businesses Are Easy Targets

Many business owners believe fraud will not happen because they know their employees, who may be long-time friends or family members. That belief is understandable, but dangerous. Fraud is often committed by the person trusted the most because that person usually has access to the money.

Smaller businesses often create opportunities without intending to do so. One person may receive money, record deposits, and reconcile the bank account. Another may create vendors, approve invoices, and prepare checks. Payroll, credit cards, and system access may be controlled by the same few people.

None of those facts prove fraud. But each creates opportunity, and opportunity is the part of fraud the business can control. Trust is good, but verification is better.

What a Fraud Assessment Should Do

A fraud assessment is a structured review of how fraud could occur inside a business. It is not an audit opinion, a guarantee, or a witch hunt. It may be used proactively or after a warning sign appears. Either way, it identifies likely schemes, tests whether controls are working, and prioritizes what needs to be fixed first.

A good assessment asks: Where does money come in? Where does it leave? Who can change records, approve transactions, override controls, and review the work? Most important: what would happen if the most trusted employee decided to steal?

The business owner does not need a three-inch binder that nobody reads. The owner needs clear risks, clear control gaps, and clear next steps.  It doesn’t even have to be perfect but only needs to be a reasonable fit for the business’ needs.

Follow the Money

Before evaluating fraud risk, understand how money moves through the business. Do not start with the general ledger. Start with the real-world process: invoicing, payments, mail, online banking, vendors, checks, ACH transfers, and bank reconciliations.

When I look at a business process, I want to know where the money starts, where it goes, who touches it, and who can change the record after the fact. That flow tells you where fraud can occur.

If an office manager can create a vendor, approve the invoice, print the check, record the transaction, and reconcile the bank account, the business does not have an accounts payable process. It has a trust exercise.

Identify the Schemes That Fit the Business

A fraud assessment should not be a generic checklist copied from a textbook. The question is, "what schemes could happen here?" Common risks include skimming receipts, fake vendors, corporate credit card abuse, ghost employees, payroll manipulation, inventory theft, and financial reporting manipulation.

Focus on likelihood and impact. A low-dollar scheme that happens every week may be more damaging than a high-dollar scheme that is unlikely. Look at the business as it is, not as the policy manual says it should be.  And look for patterns.  Fraud happens small, then grows exponentially.

Test the Controls

After the likely schemes are identified, determine whether controls actually work. Do not ask only, “Do you have a policy?” Ask, “Show me how it works.”

Useful controls include independent review of bank reconciliations, approval of new vendors, review of vendor banking changes, support for payroll changes, credit card review, and periodic review of system access. A control that exists only on paper is not a control; it is a wish.

The best controls are often simple: the owner reviews the bank statement directly from the bank, someone independent reviews the vendor list, payroll changes require written approval, and online banking requires dual authorization.

Watch Red Flags and Cyber Risks

Behavior can be a warning sign. Red flags include refusing vacation, becoming defensive when duties are reviewed, unexplained lifestyle changes, unusual closeness with a vendor, or resistance to cross-training. None proves fraud, but none should be ignored when controls are weak.

Modern fraud also does not require a checkbook. One email, one changed bank account, or one wrong click can create a loss. Cyber-enabled risks include business email compromise, wire fraud, vendor payment redirection, payroll direct deposit changes, ransomware, and unauthorized system access.

Ask whether multi-factor authentication is required, who can approve wire transfers, who can change vendor banking information, whether payment changes are verified by phone, and whether terminated employees are removed from systems immediately.

Prioritize and Build a Plan

Not every risk deserves the same attention. If everything is high risk, then nothing is high risk. Rate each risk based on likelihood, financial impact, concealment, detection, and reputational damage. This is judgment, not math.

The final product should be practical, affordable, and assigned to specific people. Recommendations may include separating duties, reviewing bank reconciliations, approving vendors and banking changes, reviewing payroll changes, requiring dual approval for wires and ACH payments, using data analytics, creating a reporting channel, developing a continuing anti-fraud culture, and training employees.

Do not overbuild the solution. A small business does not need a public-company control system. It needs reasonable controls that fit its size, risk, and budget.

The CPA’s Role

CPAs are in a strong position to help because they understand accounting systems, transaction flow, and the practical limits of smaller organizations. But the engagement letter should define the scope, limitations, and deliverable. A fraud assessment is not an audit, a guarantee, or an investigation unless the facts require one.

The CPA’s value is practical judgment: “Here is where you are exposed. Here is why it matters. Here is what I would fix first.”

For CPAs who want more training, CPA Crossings offers various CPE programs on forensic accounting, including my course, Forensic Accounting: When the Office Is a Crime Scene. The course covers what to do when a client suspects embezzlement, how to identify and preserve evidence, and how to prepare findings for possible civil or criminal proceedings.

Summary

Fraud prevention begins so that an investigation is never needed. A fraud assessment gives the owner a chance to act early by identifying where fraud could happen, what controls are missing, and what needs to be fixed before the business suffers a loss.

The bottom line is this: small businesses do not need perfect internal controls. They need controls that make fraud harder to commit, easier to detect, and harder to explain away. 


About Robert Nordlander, CPA, CFE

Robert Nordlander, CPA, CFE, is the sole shareholder of Nordlander CPA, PLLC, a boutique forensic accounting and tax resolution firm. He is the author of "Criminal Tax Secrets: What Every Defense Attorney Should Know" and "Unpaid Payroll Taxes: A Time Bomb You Can Defuse." The latest Amazon bestsellers are "Erase the Penalty: A Tax Professional's Guide to Abatement" and "From Expert to Author: Turning Insight into Influence." 


This article is provided as a complimentary resource by Robert Nordlander, CPA, CFE. Statements of fact and opinion are the author’s responsibility alone and do not imply an opinion on the part of CPA Crossings officers or members. The information contained herein does not constitute accounting, legal, or professional advice. For actionable advice, you must engage or consult with a qualified professional.