Could fraud be lurking in your organisation?
Business fraud doesn’t look like a Hollywood heist. In the real world, fraud is mundane, easy to overlook and often hidden within everyday business processes.
In this episode of talkBIG, host Katie Timms speaks to fraud and forensic expert Andrew Connelly, to unpack how fraud shows up in real life, the red flags that could signal misbehaviour and practical measures to prevent fraud from taking root.
With tales from law enforcement and forensic investigations, Andrew reveals the most common types of fraud, why growth phases, rapid scaling, and cultural shifts increase the risk of fraud and how to recognise behavioural signals like reluctance to take leave or suspicious expense patterns.
What you’ll learn:
- How fraud typically shows up inside a business
- Why early warning signs are easy to miss
- Behavioural, cultural and expense-related red flags to watch for
- How rapid growth can increase fraud risk
- The role of controls, policies and data analytics in prevention
- How AI and deepfakes are changing the fraud landscape
- Practical ways to build a fraud-aware culture
This episode is perfect for business owners, finance leaders, and risk managers who want to stay one step ahead of internal threats and build resilient, fraud-aware organisations. Tune in now.
Read transcript
Katie Timms (00:03)
Fraud in the middle market rarely looks like a Hollywood crime movie. It's usually subtle, internal, and hiding inside everyday business processes. And by the time it's discovered, the damage has already been done: financially, operationally, and reputationally. So, the real question is not if fraud could occur in your business, but rather, would you recognise it early enough to stop it? Hello, I'm Katie Timms. I'm a partner at RSM Australia and have been in the industry for over 25 years.
Welcome to talkBIG where we talk about business, money, and the economy to help you get ahead. In this episode, we'll explore how fraud actually shows up inside businesses, why it's so often missed, and what leaders can do to spot early warning signs and reduce risk in a practical way.
Today I'm chatting to fraud and forensic expert Andrew Connolly. Andrew is a Director in our Fraud and Forensic department based in Sydney.
Combining his forensic accounting expertise with a background in law enforcement, Andrew has a unique set of skills to assist investigations into suspected fraud, bribery, and corruption. He adopts a holistic approach to investigations, leveraging all available data to uncover critical facts. Andrew, welcome to the podcast.
Andrew Connelly (01:21)
Thanks for having me, Katie.
Katie Timms (01:22)
Now that does make it sound, you know, a bit like you're Liam Neeson, in Taken with your unique set of skills. Can you talk us a little bit about your background and how you ended up in this field?
Andrew Connelly (01:32)
Yeah, absolutely. And look it is a unique field. But really what we're dealing with as forensic accountants, we look at different sources of information, and we try to uncover the facts. So, it's not too dissimilar to back in my policing days, a young constable in New South Wales police, fascinated in uncovering the truth and solving mysteries and crime, all the way to when I went into the detectives and I started to work on really complex and interesting frauds. But what I actually uncovered, it was actually forensic accountants that did a lot of the groundwork before it ever got to the detective's office. So naturally that raised my curiosity. I left, I became an accountant, a chartered accountant, worked in a few different firms before I became a qualified forensic accountant. And now with RSM I lead that division, and that's brought me here today.
Katie Timms (02:27)
So, you've obviously spent a lot of time, looking at fraud and, these kinds of issues that come up in businesses. I mean, what does it typically look like in a business? Because we all have this idea and perception about what it could be, but in reality, what actually is it?
Andrew Connelly (02:40)
Good question. I think the easy accountant answer is it's always different and it depends. But unfortunately, what we see not too uncommon are a couple of areas. Generally, money has been stolen. Quite often it can be misappropriation through the misuse of a corporate credit card that's been issued to that employee. And it becomes a question of look, is that a work-related expense or is it personal gain? And that comes down to policies and procedures and controls that I can talk to a little bit later. Other areas that aren't necessarily financial related, but it's also stealing of confidential company information, so IP. We have seen that all too often, time and time again. It generally is quite often one of those two buckets, but then we always see on the news those large, extreme frauds that are multi multi million dollars. They're obviously not as common as that. They're rare, but they get the media attention.
Katie Timms (04:58)
Does technology play a part in this as well? I mean, as technology's getting more and more sophisticated, does that sometimes impact on, how it's easier to hide these kind of small little levels of fraud?
Andrew Connelly (05:08)
Absolutely. I think with AI and the trending use of AI and organisations are adopting it and it's becoming more accessible as opposed to one year ago, two years ago, most organisations have certain licenses and have a level that's beyond a standard free version of a Chat GPT or Claude. Additionally, programs such as Adobe, it's quite common now that corporate employees will have access to a super user account that will have an edit access on the Adobe. So, we're finding that people are taking invoices or receipts and using PDF editor to modify whether it's the banking details or the value of the invoice, diverting payments... Also, back to the fictitious credit card expenses, you can incur a certain expense at a certain vendor that perhaps the line item doesn't particularly resonate with a business purpose. But if you can generate an invoice that matches that amount and submit that in lieu, that's where we're seeing technology as enabler of fraud.
Katie Timms (06:16)
What you're talking about there and a lot of the issues that seem to kind of drive fraud are the people and the culture. You know, we're talking about the human element. So, the technology's all there to enable it and to perhaps put controls and things in place, but a lot of it seems to be driven by culture and behaviour.
Katie Timms (06:28)
How much of fraud is about the human rather than the process?
Andrew Connelly (06:39)
Yeah, it's a good question. I think there has to be an element that both not necessarily condones the fraud, but it's not proactive enough in communicating to the employees the stance on fraud and that it's not accepted and that you can't do this and you can do that. What's accepted? So, tone from the top I think is very important.
Obviously, you wouldn't expect the CEO to send an email to all employees saying fraud's not accepted. I think that should be a given. I mean it's in your employment contract. But I think what I mean by that is there needs to be sufficient training, whether it's an annual declaration of your code of conduct and just understanding what fraud is and isn't. Because I go back to the credit card expenses matter. because that's something we see all too common. And quite often we'll investigate expenses and we will benchmark that to the organisation's policies and try and say is that within the policy and it's permissible or is it outside and is it potentially a personal matter and then it becomes a question is it then criminal? But where I'm going with that is quite often what we will hear is an employee will say, I have done this for numerous years. It's never been picked up no one's ever challenged it.
Every time I submitted this expense, it was approved. So, what I mean by that is you need to have the sufficient controls, policies, and managers that scrutinise and challenge those expenses. Because you have to tell the employee, look, this is actually not compliant. It's borderline personal, you either need to repay that or cease that continued behaviour. I think as well culturally you need managers that take on fraud ownership. So, they're tasked with certain areas of fraud prevention, detection, and response. That needs to be clearly communicated. And equally, there should be an investigation or a response plan that, in the worst case, a fraud is identified. An organisation needs to have a plan ready of knowing what they're going to do. So, for example, it might be a blanket policy that every fraud will be referred to the police.
I mean, that is a significant deterrent when you know police are gonna be involved. Equally, are you going to investigate it internally or are you going to perhaps from an independence or objective assessment, especially if you're a government organisation, it's very common. Are you going to outsource that? So, there's no challenge about it was investigated by a manager and there wasn't a sufficient segregation. And then I think the last thing as well that's very important, in respect of the board, now.
There are different sizes of organisations. There are executive directors that are heavily involved in the operations of the business. And there's the non-executive directors that obviously are very high level. But fraud, corruption and how they're treated and dealt with internally should be a standing agenda on board meetings, just so that they're aware of what's happening in the organisation.
Katie Timms (09:38)
I think you've raised a couple of really interesting things there because you've talked about I mean we started off talking about things like using tech to edit invoices and stuff which is very I mean very blatant fraud right and then we've kind of wandered into the interesting space of credit card expenses which are maybe borderline or not and do you think there's enough understanding in organisations, by staff of actually that is still fraud, using a credit card for something that maybe you do know is a grey area.
That that is fraud. I mean, do you think that businesses spend enough time on that piece as well?
Andrew Connelly (10:09)
My take on that is historically no, I don't think they do because l like I said, all too often I'll be investigating that. and it may involve a very targeted investigation towards a certain individual or individuals, or it might be a broader review into credit card usage for management to really see where it's being used and the appropriateness of that going forward. But I think historically, no, that was an area you know that level of discretionary spend and it depends on the nature of the organisation. I mean generally those services such as professional services that have a heavy business development component have a lot higher credit card expenditure than other areas of certain organisations such as a government department that traditionally they won't condone employees to have lunches and dinners with potential clients and referrals.
So, I think historically there wasn't a clear line between what's personal and what's business. And employees would often tell me as part of my investigations into those expenditure that it wasn't clear to them what is permissible, what's not permissible. Equally financial thresholds. So different organisations have different financial thresholds around, look, if it's a lunch expense under this dollar value, you don't need permission.
If it's over this dollar value, you need a certain manager to approve that in advance. So, all too often, definitely there was a bit of a gap in awareness. But I think what we're seeing now with the economy going the way it's going, discretionary expenditure is being reined in, and it is being more scrutinised and challenged.
Katie Timms (11:48)
Okay. And I mean, we've talked a little bit as well about, the fraud being these small little bite size amounts that people don't notice, you know, do you think that's where the big risk is, in particular where we're talking about, limits and discretionary spend and all those sort of things. Is that actually a bigger threat than the big fraud, which is the big, big money amount?
Andrew Connelly (12:08)
Yeah, I mean it's very difficult to sort of answer this as a blanket comment, but absolutely. I mean the big fraud will always be there, but it's the matter of the amount of times that they're brought to light and identified, and you'll see them in the media, I think is insignificant to the smaller frauds that cumulatively add up.
And I think it's just always comes down to the risk tolerance of the organisation and how much you're prepared to weigh on a cost benefit of the investment into controls, systems, data analyst data analytics, external consultants to look at that versus the potential benefit.
Katie Timms (12:50)
You've used some like roles there. So, data analytics, you know, external consultants, all these sorts of things. These are things that I suspect big business would just be like, yep, use those all the time. I understand how they fit.
Katie Timms (18:10)
So, you mentioned then as well, how do you bring this to the attention and things? I mean, how do businesses look for the red flags? You know, like what is it that is gonna, if it's not someone that's willing to put their a) their hand up and confess, which I'm assuming doesn't happen all that often, or, you know, b) being dobbed in by someone else, where do you find the red flags? What are you looking for?
Andrew Connelly (18:30)
I mean good question. Look, there are several red flags. They're applicable to all organisations, but every organisation's different. It depends on what your business does, where is your cash kept, what is your source of revenue, and what are your biggest expenses. I think you need to look at that. I think you need to do a fraud risk assessment and understand your business's risk or exposure to fraud. Document different processes, the key processes that you undertake. Because you need to understand internally what it is that you do, how you do it, and is it the right way to do it? Do the staff know? Is it articulated? You then need to know your controls, test your controls, and then I think you need to have that externally validated or objectively assessed.
Even if different organisations have different levels of maturity of their systems, the term data analytics I think does scare organisations off that there's an assumption that it's expensive, it's only specialized software or systems that can be implemented. I don't think that's necessarily true. I think if you've got systems that record basic elements such as transactions, employees leave, vendor details, perhaps even better than that if you've got an audit log configured in your CRM or finance system that records different changes to bank account details for vendors and employees, there's a lot of things that you can do. Ideally, the best-case scenario would be there's almost live time data analytics running in the background, monitoring suspicious behaviour, unordinary payments, round sum payments, unusual modification to bank account details. That would be an ideal situation. But if that's not ideal and an organisation perhaps isn't as mature as that, on their journey and their life cycle. It may be a little bit more manual, but whether it's weekly, fortnightly, or monthly, it would be ideal that it is routine. You can look for unusual payment activity, for example. So, whether it's round dollar payments, duplicate payment amounts. Also, if there's different financial delegation levels within your organisation, such as managers are able to incur or approve payments at a certain dollar threshold. Looking for payments that are always just below that figure is a red flag.
Now, just a caveat; red flag doesn't mean fraud. It just means look, on its on its own, bona fide in the absence of other information that corroborates that payment, it is a bit suspicious if all those transactions are just below that amount. In addition to looking at your audit logs and bank account changes, especially when a bank account change is made twice in quick succession. That's a very big red flag. That can mean an employee or an insider has changed the vendor's bank account details, processed a payment to another bank account to divert a payment to them and then changed it back to the bona fide bank account. That’s a red flag.
Andrew Connelly (18:30)
Other areas are monitoring annual leave. Flag. Generally, the stereotype, the employee that's reluctant to go on annual leave because they're concerned or scared that once they go on leave, their pattern of behaviour will be sort of undone and identified. Additionally, another area you could look at or scrutinise is controls that are constantly overridden or there's been approval sought as an exemption to not process that. For example, perhaps a client onboarding, perhaps it's standard process that you undertake AML checks, money laundering checks, bank verification checks. But perhaps in certain instances that can be overridden by a certain employee requesting it and then being approved. That's a bit of a red flag. In addition to also just reviewing your data.
So, for example, in your vendor master file. If you've got duplicate vendors with very similar names or duplicate employees that have the same bank account number, that's quite concerning. That can be an example of what we call ghost employees. Payments that are being processed outside ordinary business hours or on weekends, and other unusual journal entries and payments being held in suspense accounts, that's a red flag.
Payments that are sort of inconsistent with historical trends. And I think lastly, and I touched on it before, a red flag is a culture that either you don't have avenues to speak up, or what we also see all too common unfortunately, is an organisation will say, yep, we've got a whistleblower service, we've got a phone line, an email address, but we've had it for five years and not once have we received a report.
And unfortunately, that's something that they can be proud of, but I think it's equally something that that should be challenged and look, it's great if there's absolutely no concerns about fraud, but equally do your employees feel comfortable speaking up? Is it anonymised or do they have to disclose their name? Because that might discourage them. So, there's some elements that can be considered.
Katie Timms (23:45)
That one about the employee not taking leave is a fascinating behavioural red flag as someone that doesn't take enough annual leave. Guys, I hope that's not why you think that I'm not going on holidays! What are like actual behaviours that you tend to see that are red flags? You know, are there things that have tripped people up in the past other than not taking leave, which I'm gonna, check on all of my people with?
Andrew Connelly (24:05)
Probably not behaviours, but I think there's certain elements that on average, so the law of averages, are quite common amongst those larger fraudulent instances. So generally, it's someone relatively senior, upper or middle management, they've been within the organisation for up to five or ten years. There's a strong element of trust. Unfortunately, I'm gonna pick on the finance people. Generally, in the finance or a monetary fraud. Internally it's someone within finance accounts payable, accounts receivable, someone that has sufficient access or colludes with someone else internally to orchestrate a fraud scheme and organises, I'll process it, you approve it. But in terms of those traits, they're all different and behaviours, they're all different. That's where I think data analytics and employee monitoring can reap its rewards where you're looking at again logging outside ordinary business hours, processing certain payments, those sorts of behavioural indicators rather than at the individual themselves.
Katie Timms (25:12)
I really desperately want to ask you for a story of someone who's been tripped up by something really obvious, but I'm assuming that you can't share anything.
Andrew Connelly (25:20)
Look it's always difficult because quite often, we're engaged in the background and clients don't want to necessarily have something disclosed. But let me think of one. Maybe we can come back to that. I'll think of one.
Katie Timms (25:35)
Okay, think about it, because I'm gonna want you to finish with a really interesting story. Even reach back to your law enforcement days. Because this is what everyone loves, right? The stories.
Andrew Connelly (25:44)
Yeah. Yeah.
Katie Timms (25:45)
So, we talked a lot about the, you know, different life cycles of the business and the smaller business versus the bigger businesses and at what point you need to stop and step back. But tougher economic climate, resources may be more limited for certain businesses.
Where should people be putting their priorities? What are the things, to do if you don't have the ability to, throw everything at it?
Andrew Connelly (26:09)
You need to look at where your discretionary expenditure is and look at your controls. So, I think some key areas that need to be looked at immediately because I am starting to see it, would be, for example, usage of AI within your organisation. And I think there will be some organisations that will have issues in the future where employees leave the organisation. And I'm talking about just the normal employee that's leaving under good circumstances, they've gone to a new employer, perhaps an external promotion, and perhaps during their time at the organisation they're originally at, they may have used ChatGPT or Claude for legitimate purposes such as trying to succinctly summarise employment contracts, leases, finance agreements, putting the documentation in that platform, asking for a summary, and then using that summary as part of their work.
What we're starting to see now is all too often that Claude or Chat GPT platform is linked to their personal email address. And what happens is when they leave the organisation, even though you perhaps hand back your laptop and you're cut off access from the organisation, you've still got client or confidential IP retained within your program, your subscription. And how do you then manage that and delete that and provide some sort of assurance that you're not going to use that. Like I said, all too often it can be completely innocent. It's forgotten about and then it's identified later. But that could be another avenue that could be trying to bypass certain controls. What I have seen is all too often, organisations will restrict the use of USB devices being used. But I think AI platforms are still a weakness that need to be monitored.
Not only for that reason. Obviously, there's other areas such as hallucination and reliance. And that's a different topic for a different expert. But I would say look at that. That's what I would call low-hanging fruit, in that you need to look at that, strengthen that, tighten that. And that may be perhaps if your organisation warrants it completely restricting the use of Chat GPT or Claude platforms and only rely on an internal licensed platform where it can be monitored what's uploaded.
And it's linked to a work email, not a personal email. So, I think that's one area.
Katie Timms (28:28)
Yeah. You talked then as well about the staff leaving and taking things with them. And you did refer to that back at the beginning and we've talked about fraud as in, you know, dollars and things like that, but that IP fraud as well as there, are there specific things that, businesses can put in place to try and other than the AI potential whoopsie, to stop people from stealing things on the way out?
Andrew Connelly (28:49)
Yep, I think absolutely. I see this all too often. There are areas that you can do and that should be ideally restricting the use of external USB devices or hard drives, or at least restricting it, but it could be used under manager approval or through your IT's approval and it's monitored what you put on there because that's an easy leakage of confidential information. I think secondly as well, the usage of personal email platforms that let's be honest; most people will have that open in the background and you're monitoring emails. But I think restricting attachments being uploaded to that personal email, I think it's all well and fine to be able to communicate, if necessary, on that. But the ability to restrict uploading documents to personal email platforms and other areas such as the usage of non-organisation sanctioned cloud platforms, so Google, Cloud, etc. So, what we will see all too often is with clients, if you have to send or receive very large documents that the ordinary email system can't handle. Sometimes people are using their personal Google Drive to send and receive documents, but unfortunately that's all too often their personal email address. So, I think restricting that
I think as well, like I said, credit cards, monitoring that. Many different organisations have various levels of maturity of how they monitor that. Some are very loose and it's very much transactions incurred. All too often there's not even a supporting document provided to substantiate that. It's largely just approved that approved and paid every month. there are external third-party platforms that you can use.
Help you monitor that we'll use analytics and some areas to make sure that their fraud is minimised. Monitoring annual leave, I think that's very important. And there's genuine reasons that people like to accumulate annual leave. Maybe they've got a big trip to Europe planned for next year. Perhaps they're putting it off this year for reasons which I won't go into, but next year they want to go. So, they might say, look, here's a commitment that my annual leave is going to get high, but I'm intending to take one or two months next year and I'll get it in line with an ordinary level. I think as well something that we haven't touched on as well is the onboarding of new staff. And are you undertaking appropriate reference checks, criminal history checks? I don't think the cost is that significant in terms of the potential benefits that it brings and it should be considered.
Katie Timms (31:30)
So, Andrew, final thoughts. You know, is this something that you see, given the movement in technology and AI and all this, that it's gonna become more and more important? Like this isn't something that's gonna get, you know, tech's not gonna make this less of a risk. Do you think this is a space that is gonna just become more and more of a risk for businesses?
Andrew Connelly (31:49)
I think it is. I think the trending concern now is the use of deep fakes to really trick and fool organisations into making rash decisions. We've heard of cases overseas, not yet in Australia, thankfully, but I think it won't be too long where senior finance people have received a call, even a video call from what was purported to be the CEO.
But it was actually a deep fake and pressured to make payments in excess of $20m to different bank accounts. And obviously they challenged that and they scrutinised that. That's what led to the video call. And that's what reassured them. So, I feel like deep fakes is an area that very much in its infancy, at least in an Australian context. But I do worry where that's gonna go. I think it's focusing on what I want to call the low hanging fruit. What's within your control, what's feasible? You need to get the basics and the foundations right first. And hopefully I'll give you some tips.
Katie Timms (32:48)
As Andrew has told us, fraud doesn't happen in isolation. It happens in these gaps between process, behaviour, and oversight. The organisations that succeed are the ones that stay alert and act early. Andrew, thank you so much. I'm now terrified, as I always am with these things, but I really appreciate you sharing all of that. I would have loved to have heard a behind the scenes story, but I think it's probably inappropriate to ask for one. So, thank you so much for joining me on the podcast today.
Andrew Connelly (33:15)
No, you're welcome. You're welcome.
Katie Timms (33:17)
If you found this episode helpful, please share it and subscribe for more conversations that matter to business leaders. Thank you for joining us on talkBIG. Please subscribe and leave a review.
Andrew Connelly (33:27)
Thank you.