The fraud tree is the Association of Certified Fraud Examiners’ classification of occupational fraud, the fraud committed by people against the organisations that employ them, and it has organised the field since the first Report to the Nations in 1996. It has three branches, corruption, asset misappropriation and financial statement fraud, and under them about fifty named schemes, each of which describes a mechanism rather than a motive: how the money or the misstatement is actually produced. That is why it is useful to an auditor. A taxonomy of mechanisms is a taxonomy of controls, because every scheme on the tree defeats a specific control or exploits its absence, and every scheme leaves a specific shape in the data. The ACFE’s Occupational Fraud 2026: A Report to the Nations, covering 2,402 cases in 143 countries, gives the tree its current proportions: asset misappropriation appeared in 90 percent of cases with a median loss of 100,000 dollars, corruption in 45 percent with a median of 150,000, and financial statement fraud in 6 percent with a median of one million dollars; 38 percent of cases involved more than one branch, and the median scheme ran for twelve months before detection, twenty-four for financial statement fraud.
This guide walks the whole tree, branch by branch and scheme by scheme, with what each scheme is, who typically commits it, the red flags that precede detection, the control that prevents it and the analytic that detects it. It then covers how practitioners use the tree (to seed a fraud risk assessment, to map an analytics program, to classify an investigation, to train staff, and to frame an insurance claim), what the tree deliberately leaves out, and how the frauds in this site’s worked examples sit on it. It is the reference behind the fraud risk assessment guide and the scheme catalog in the fraud risk management guide.
In this guide
- The three branches and what unites each
- Corruption: conflicts of interest, bribery, gratuities, extortion
- Asset misappropriation: cash on hand and cash receipts
- Asset misappropriation: fraudulent disbursements
- Asset misappropriation: inventory and all other assets
- Financial statement fraud: overstatements and understatements
- The numbers behind the tree: what the 2026 report adds
- How practitioners use the tree
- Where this site’s worked examples sit on the tree
- What the tree leaves out, deliberately
- Where to go next
The three branches and what unites each
The branches differ in who benefits and how the loss shows up. Asset misappropriation is theft: the perpetrator takes cash or property, and the loss is a missing asset concealed by a false record. Corruption is influence: the perpetrator uses their position to benefit themselves or a third party in a transaction, and the loss is an overpayment, a bad contract or a lost opportunity that the records show as a normal transaction. Financial statement fraud is misrepresentation: the perpetrator, usually senior, misstates results to obtain a benefit (a bonus, a share price, a covenant, a financing), and the loss falls on the people who relied on the statements. The table gives the proportions from the 2026 report and the structural facts an auditor should carry.
| Branch | Share of cases (2026) | Median loss (2026) | Who typically commits it | What unites the schemes |
|---|---|---|---|---|
| Asset misappropriation | 90 percent | 100,000 dollars | Employees and managers with access to the asset; the most frequent branch and the least costly per case | A missing asset, concealed by a false or missing record; detectable by reconciling what exists to what is recorded |
| Corruption | 45 percent | 150,000 dollars | Purchasing, sales and management staff who control a transaction; frequently involves an outside party | A transaction that is real but influenced; detectable by patterns across transactions and by relationships, rarely by a single document |
| Financial statement fraud | 6 percent | 1,000,000 dollars | Executives and senior finance staff; the least frequent branch and the most costly, with the longest duration (24 months median) | A record that is complete and internally consistent but false; detectable by analysis of estimates, timing and top-side entries |
Corruption: conflicts of interest, bribery, gratuities, extortion
Corruption has four sub-branches on the tree. Conflicts of interest are cases where an employee has an undisclosed personal interest in a transaction: purchasing schemes, where the employee steers business to a vendor they own or benefit from, and sales schemes, where they give a customer they are connected to unauthorised terms, discounts or credits. Bribery is a payment to influence a decision: invoice kickbacks, where a vendor inflates invoices and shares the increase with the employee who approves them, and bid rigging, where a procurement competition is fixed through specification tailoring, leaked information, bid rotation or arrangements among bidders. Illegal gratuities are rewards given after a decision rather than to procure it. Economic extortion is the mirror of bribery: the employee demands a payment as the price of a decision. The unifying fact is that every corrupt transaction is a real transaction with a genuine document trail, which is why corruption is found through patterns and relationships rather than through document tests.
| Scheme | How it works | Red flags | Control that prevents it | Analytic that detects it |
|---|---|---|---|---|
| Conflict of interest: purchasing | An employee directs purchases to a vendor they or a relative own, at inflated prices or for unnecessary goods | Sole-source vendor tied to one requester; vendor address, phone or bank matching an employee; a vendor created shortly before its first order | Conflict-of-interest disclosure with annual attestation; vendor-master screening against the employee file at creation; independent vendor approval | Vendor-employee matches on bank, address, phone; single-requester vendors above a spend floor |
| Conflict of interest: sales | An employee grants a connected customer unauthorised discounts, credits, terms or priority | Discounts and credits concentrated on one rep-customer pair; write-offs for one customer; pricing exceptions approved by the rep’s manager only | Pricing exception approval outside sales; credit and write-off approval independent of the rep | Discount, credit and write-off concentration by rep-customer pair against the population |
| Invoice kickbacks | A vendor overbills and pays part of the excess to the approving employee; the match passes because the buyer accepts the price | Price rising at every renewal without re-bid; invoices inside the tolerance band; a buyer who blocks rotation | Price benchmarking; competitive re-bid cycles; rotation of buyers; approval of price changes outside purchasing | Price creep by item and vendor; unit prices against contract and market; sole-source renewal analytics |
| Bid rigging | The competition is fixed: specifications written for one bidder, bids leaked, bidders rotating wins or agreeing prices, the loser subcontracted by the winner | Identical bid arithmetic errors; bids with the same formatting; the same winner or a rotation; a losing bidder paid by the winner | Sealed bids opened by a panel; specification review independent of the requester; bidder rotation analysis; subcontractor disclosure | Bid pattern analysis across tenders; bid-loser-as-subcontractor test; winner concentration by buyer |
| Illegal gratuities | A gift or payment after a favourable decision, without a prior agreement | Hospitality and gifts clustered around contract awards; a vendor’s expense claims naming employees | Gifts and hospitality register with thresholds; post-award cooling-off review | Gift register against award dates; expense claims from vendors referencing employees |
| Economic extortion | An employee demands payment from a vendor or customer as the price of a decision | Vendor complaints or sudden withdrawals; unexplained concentration of one vendor’s business with one employee | Vendor hotline and independent vendor relationship reviews; rotation | Vendor churn around one buyer; hotline analysis by department |
Asset misappropriation: cash on hand and cash receipts
The tree splits cash schemes by when the cash is taken relative to when it is recorded. Theft of cash on hand is the taking of cash already in the organisation’s custody: a till, a safe, a petty cash box, a deposit bag. Theft of cash receipts divides into skimming, where the cash is taken before it is recorded (so the books never know it existed), and cash larceny, where it is taken after recording (so the books show a shortage that must be concealed). Skimming itself branches into sales skimming (unrecorded or understated sales), receivables skimming (concealed by write-offs, by lapping, where later receipts cover earlier thefts, or unconcealed), and refunds and other. The distinction matters for the auditor because skimming leaves no direct record and is found by comparing the organisation’s records with something outside them (customer statements, expected revenue, a second count), while larceny leaves a shortage and is found by reconciliation performed by someone independent.
| Scheme | How it works | Red flags | Control that prevents it | Analytic that detects it |
|---|---|---|---|---|
| Theft of cash on hand | Cash taken from a till, safe or deposit before it reaches the bank | Till shortages concentrated on one cashier or shift; deposits below register totals; safe counts by one person | Independent cash counts; dual custody of deposits; deposit intact and daily | Shortage by cashier and shift; deposit-versus-register variance by location |
| Sales skimming | A sale is made and the cash pocketed without recording, or recorded at a lower amount | Sales falling while activity indicators (footfall, stock movement, customer counts) do not; a location’s cash-to-card ratio below peers | Point-of-sale recording enforced by receipt issuance and customer statements; stock reconciled to sales | Cash-to-card mix by location and cashier; sales against consumption or stock relief |
| Receivables skimming: write-off schemes | A customer’s payment is stolen and the balance written off as uncollectible | Write-offs by the person who receives payments; customers with write-offs and continued trade | Write-off approval independent of receipts and collections; watch-list for written-off accounts | Write-off-then-receipt; write-offs by user |
| Receivables skimming: lapping | Customer A’s payment is stolen; customer B’s later payment is applied to A, and so on | Applications delayed; payments applied to a customer other than the remitter; a clerk who never takes leave | Cash application independent of receipt handling; remittance data imported, not keyed; mandatory leave | Lapping signature: cross-customer applications and application delays |
| Refund and other skimming | Refunds issued for returns that did not happen, or credits skimmed as cash | Refunds concentrated on one employee; refunds without matching sales | Refund approval independent of the cashier; refunds to the original tender only | Refund concentration by user; refunds without an originating sale |
| Cash larceny | Recorded cash is taken from the deposit or the till after recording | Reconciliation differences described as timing; deposits lagging collections; the same person collecting and reconciling | Independent bank reconciliation from the bank file; deposit listing agreed to bank credit by someone else | Rolling reconciling items; deposit lag by depositor; deposits credited short of listings |
Asset misappropriation: fraudulent disbursements
Fraudulent disbursements are the largest group on the tree and the one that produces most of the analytics catalogs on this site. The perpetrator causes the organisation to pay out money through its own processes, so the payment is recorded, approved and reconciled; the fraud is in what it was for. Five sub-branches: billing schemes (shell company invoices, invoices from a non-accomplice vendor manipulated by the employee, and personal purchases put through the company); payroll schemes (ghost employees, falsified wages or hours, and commission schemes); expense reimbursement schemes (mischaracterised, overstated, fictitious and multiple claims); cheque and payment tampering (forged maker, forged endorsement, altered payee, and the authorised maker who writes cheques to themselves, extended in practice to electronic payments and beneficiary changes); and register disbursements (false voids and false refunds). Billing schemes have been the most common asset-misappropriation scheme in every recent Report to the Nations, appearing in roughly one case in five, and cheque and payment tampering is consistently among the costliest per case.
| Scheme | How it works | Red flags | Control that prevents it | Analytic that detects it |
|---|---|---|---|---|
| Billing: shell company | The employee creates a vendor that exists only on paper and approves its invoices for goods or services never provided | Vendor with a PO box, no tax ID, a personal-sounding name, a bank matching an employee; invoices with round amounts and no PO | Independent vendor onboarding with verification; three-way match; approval limits with no self-approval | Vendor-employee matches; shell-profile scoring; new vendor fast payment; sequential invoice numbers |
| Billing: non-accomplice vendor | The employee manipulates a real vendor’s invoices (double payment, then intercepts the refund; or overpays and requests a refund to themselves) | Refund cheques from vendors; duplicate payments followed by credits | Duplicate-payment check with fuzzy matching; vendor refunds received by someone outside payables | Duplicate and near-duplicate payments; refund tracking |
| Billing: personal purchases | Personal goods bought on company accounts or cards and coded as business expense | Purchases shipped to home addresses; consumer goods coded to supplies; card spend at odd merchants | Receiving independent of the requester; purchasing card merchant category controls and review | Ship-to address analysis; merchant category outliers; weekend and holiday purchases |
| Payroll: ghost employees | A fictitious or terminated employee is kept on the payroll and the pay collected by the perpetrator | Employees with no deductions, no leave, duplicate bank accounts or addresses; pay after termination | Payroll-to-HR reconciliation; HR creates, payroll pays, neither does both | Payroll to HR and badge or VPN activity; duplicate bank accounts; pay after termination |
| Payroll: falsified wages and commissions | Hours, rates or commission bases inflated by the employee or a colluding approver | Overtime concentrated in one approver’s team; rate changes by a payroll user without HR authority | Rate changes originate in HR; overtime approved by a manager outside the team; commission calculation independent of sales | Overtime and approval loops; rate changes by user; commission against booked and collected sales |
| Expense reimbursement | Claims that are mischaracterised, overstated, fictitious or submitted twice | Round-number claims; receipts just under the receipt threshold; the same receipt across claims; claims for days on leave | Receipts required; manager approval with system duplicate checks; policy thresholds enforced | Near-duplicate claims; threshold hugging; claims against calendar and travel data |
| Cheque and payment tampering | A cheque or electronic payment is forged, altered, or issued by an authorised signer to themselves or an accomplice | Cheques with altered payees; payments to employees from the vendor run; beneficiary changes followed by payments | Positive pay with payee match; dual control on release; beneficiary-change verification by call-back | Cleared-cheque payee against register; bank-change-then-payment; payments to employee bank accounts |
| Register disbursements | False voids or refunds processed at the register with the cash removed | Voids and refunds concentrated on one cashier; refunds without a return; voids after the customer has left | Void and refund approval by a supervisor; refunds to the original tender; surveillance | Void and refund rates by cashier and shift; refunds with no sale |
Asset misappropriation: inventory and all other assets
The non-cash branch covers stock, equipment, supplies, securities, data and anything else the organisation owns. Misuse is the unauthorised use of an asset without taking it (a vehicle, a system, a customer list); larceny is the taking. Larceny divides by mechanism: asset requisitions and transfers, where the perpetrator uses the organisation’s own paperwork to move the asset to where it can be taken; false sales and shipping, where goods are shipped to an accomplice against a fictitious or unpaid sale; purchasing and receiving schemes, where goods are ordered and diverted at receipt or recorded as short; and unconcealed larceny, where the asset is simply taken and the records are left to show a shortage. The auditor’s leverage is the adjustment: almost every concealed inventory theft ends in a stock adjustment, a write-off or a count variance resolved without investigation, which is why the inventory audit guide treats adjustment analytics as the first test.
| Scheme | How it works | Red flags | Control that prevents it | Analytic that detects it |
|---|---|---|---|---|
| Misuse | Company assets used for personal benefit: vehicles, equipment, systems, data, staff time | Mileage and fuel out of line with routes; equipment off-site; data exports by users with no need | Asset usage logs; telematics; data access controls and export monitoring | Fuel and mileage against route data; after-hours system activity; large exports |
| Larceny: requisitions and transfers | Stock requisitioned or transferred on paper to a location or purpose that allows it to be taken | Transfers that never arrive; requisitions to cost centres with no consumption; one-sided transfers | Transfers received in the system by the receiving location; requisitions approved and reconciled to consumption | Transfer aging and one-sided transfers; requisitions against consumption by cost centre |
| Larceny: false sales and shipping | Goods shipped to an accomplice under a fictitious sale, a sale never invoiced, or a sale later credited | Shipments without invoices; credits after shipment; customers with unusual returns | Shipping only against approved sales orders; invoicing triggered by shipment; credit approval independent | Shipments without invoices; credit memo concentration after shipment; ship-to address anomalies |
| Larceny: purchasing and receiving | Goods received and recorded short, or received and diverted before put-away; or over-ordered and the excess taken | Receipts posted before arrival; short receipts concentrated on one receiver; over-ordering of resalable goods | Receiver independent of the buyer; receipts from a dock count; receiving discrepancies reported and investigated | Receipt-before-arrival; short-receipt concentration by receiver; order quantity against consumption |
| Larceny: unconcealed | The asset is taken and the shortage left to be found, often blamed on error or external theft | Persistent count variances at one location; shrink concentrated in resalable categories | Physical access control; blind cycle counts by independent counters; adjustment approval | Count variance persistence; shrink by location and category; adjustment concentration |
Financial statement fraud: overstatements and understatements
Financial statement fraud is the branch where the perpetrator does not take an asset but misstates the accounts, and the tree divides it by direction. Net worth or net income overstatements have five mechanisms: timing differences (recording revenue early or expenses late, including cut-off manipulation and channel stuffing); fictitious revenues (sales that never happened, to customers real or invented); concealed liabilities and expenses (omitting, deferring or capitalising costs); improper asset valuations (inventory, receivables, capitalised development, goodwill and other estimates pushed the wrong way); and improper disclosures (omitting related-party transactions, contingencies or going-concern doubts). Understatements use the same five in reverse, usually to reduce tax, royalties, an earn-out or a regulatory obligation, or to build reserves for a future period. The auditor’s leverage is that all five mechanisms run through estimates, timing and top-side entries, which are precisely the areas a journal entry analytics program and a period-end review can cover in full; the financial statement fraud guide works through each mechanism with the cases that made them famous.
| Mechanism | How it works | Red flags | Control that prevents it | Analytic that detects it |
|---|---|---|---|---|
| Timing differences | Revenue recognised before it is earned; expenses deferred; shipments pulled forward or held open at period-end | Sales spikes in the last days of a period; reversals in the first days of the next; bill-and-hold arrangements | Revenue recognition policy enforced by system triggers (shipment, acceptance); cut-off review independent of sales | Period-end spike and reversal analysis; days-to-reversal on late-period invoices |
| Fictitious revenues | Sales invented, to real customers who did not order or to customers who do not exist | Receivables growing faster than sales; customers that never pay; sales with no shipment or delivery evidence | Invoicing only from shipment or acceptance; customer onboarding independent of sales; receivable confirmations | Invoices without shipment; receivable aging by customer; new customers with large sales and no payments |
| Concealed liabilities and expenses | Invoices held, accruals omitted, costs capitalised that should be expensed, obligations left off the balance sheet | Accrual balances falling while activity rises; post-close invoices; capitalisation rates climbing; suppliers complaining of late payment | Accrual completeness review from purchase commitments and receiving; capitalisation policy applied by a reviewer independent of the project | Post-close invoice review; accrual against purchase-order commitments; capitalisation rate trends by project |
| Improper asset valuations | Inventory, receivables, goodwill, capitalised costs or fair values carried above what evidence supports | Reserves that move with the quarter’s needs; allowances unchanged despite aging deterioration; impairment tests that always pass | Estimate methodologies documented and applied consistently; reviewer independent of the estimate’s owner; audit committee review of significant estimates | Reserve movement against drivers; allowance against aging; estimate sensitivity analysis |
| Improper disclosures | Related-party transactions, contingencies, subsequent events or going-concern doubts omitted or minimised | Transactions with entities connected to executives; legal matters absent from the disclosure checklist; management reluctance on going-concern | Related-party register with annual attestation; disclosure committee; legal letters obtained directly | Counterparty matching against the related-party register; contract review for guarantees and side letters |
| Understatements | Revenue deferred, expenses accelerated or reserves built to reduce tax, royalties, earn-outs or a regulatory measure | Results below plan in a good year; reserves without a driver; effective tax rates that fall without explanation | The same estimate and cut-off controls, applied in both directions | Reserve builds against drivers; deferred revenue against contract terms |
The numbers behind the tree: what the 2026 report adds
The tree tells you what the schemes are; the Report to the Nations tells you who runs them, how they are caught, and what reduces the damage, and the 2026 edition’s figures are worth carrying into any assessment or training session. Who: the perpetrator’s level drives the loss more than the scheme does. Owners and executives produced a median loss of 475,000 dollars per case, managers 125,000, and staff-level employees 50,000, and executive frauds ran for a median of 23 months against 12 overall. Tenure compounds it: perpetrators with more than ten years’ service produced a median loss of 200,000 dollars, four times that of those in their first year, because tenure buys trust and trust buys opportunity. How caught: tips remain the single largest source at 43 percent of cases, more than half of them from employees, with internal audit at 15 percent and management review at 13 percent; email and web reporting channels have now overtaken telephone hotlines. Why it happened: in 33 percent of cases there was simply no control, in 19 percent management overrode the control that existed, and in 18 percent nobody reviewed. What helps: organisations with management review of controls saw median losses 55 percent lower, with proactive or automated data monitoring 53 percent lower, with surprise audits 50 percent lower, and with fraud awareness training for staff and managers 44 percent lower. And what to watch for: 84 percent of perpetrators displayed at least one behavioural red flag, the most common being living beyond one’s means (39 percent), financial difficulties (29 percent) and unusually close relationships with a vendor or customer (17 percent), which is why the corruption branch’s tests are relationship tests. The numbers do not identify a fraudster; they tell an assessment where to put the weight, and they say, every edition, that the scheme most organisations plan for (the junior employee with their hand in the till) is the one that costs least.
How practitioners use the tree
Five uses, in the order they earn their keep. As the library for a fraud risk assessment: the tree is the starting list of scenarios for every process workshop, and the fraud risk assessment guide shows how a forty-scheme library becomes a forty-scenario register. As the map for an analytics program: every scheme on the tree has a detective analytic in the tables above, and a function that builds its catalogs by branch (the AP, payroll, journal entry and procurement fraud catalogs on this site are organised that way) can show the audit committee which branches it monitors continuously and which it does not. As the classification for investigations and the hotline: coding every allegation and every confirmed case to a tree scheme turns the incident history into data, which is what lets an organisation compare its own pattern with the Report to the Nations and notice, for instance, that its billing-scheme rate is three times the benchmark. As the syllabus for training: staff and managers who can name the scheme they are looking at report it; the 2026 report’s finding that training both groups cut the median loss from 150,000 to 84,000 dollars is the business case, and the tree is the curriculum. And as the frame for insurance: crime and fidelity policies define covered losses in terms that map to the branches (employee theft, forgery, computer and funds-transfer fraud), and a claim written in the tree’s language is a claim the insurer understands.
Where this site’s worked examples sit on the tree
The frauds and near-frauds in this site’s worked examples were written to sit on the tree, and placing them is a useful exercise in classification. The Dayton depot driver at MidState Beverage, who diverted 18,400 dollars of route collections over five months and was exposed by a customer complaint (the fraud risk management guide), committed theft of cash receipts, concealed through the self-approved override adjustments that the route cash audit later found across 1,412 items. The depot manager’s undisclosed trucking vendor found by the AP analytics run is a conflict of interest, purchasing scheme; the HR administrator’s seventeen self-approved rate changes in the payroll run are a falsified-wages payroll scheme, and the eleven people paid after termination were a ghost-employee condition whether or not anyone collected the money. At Brightwater Foods, the plant supervisor’s spouse’s cleaning contractor in the procurement fraud run is a conflict of interest, purchasing scheme, and the two tenders where a losing bidder was paid by the winner are bid rigging in its loser-as-subcontractor form. The Lakeshore Bancorp wire-platform user who could enter and release wires, in the deficiency evaluation guide, is the opportunity for an authorised-maker payment-tampering scheme, which is why it was rated as it was despite no loss. And the Macy’s employee who concealed about 151 million dollars of delivery expenses over nearly three years, disclosed in November 2024, without taking any money, is a concealed-expenses financial statement fraud committed to hide an initial error, which is the branch’s most common origin story.
What the tree leaves out, deliberately
The tree classifies occupational fraud: schemes committed by employees, managers and executives against their own organisation, sometimes with outside help. It does not classify fraud against the organisation by outsiders acting alone (business email compromise, account takeover, customer and application fraud, vendor overbilling without an insider), fraud by the organisation against others (mis-selling, market abuse, sanctions evasion, which are compliance failures rather than occupational fraud), money laundering, or cyber crime as such, although a cyber intrusion may be the means of an occupational scheme. A fraud risk assessment therefore uses the tree for the inside and adds an outside branch, as the assessment guide does, with business email compromise as its largest single item: the FBI’s Internet Crime Complaint Center recorded 3.05 billion dollars of business email compromise losses in 2025. The other deliberate omission is motive. The tree says how, not why, and the why (pressure, opportunity, rationalisation, capability) is the fraud triangle’s territory, covered in the fraud red flags guide. Classification and motive are separate questions, and the investigator who confuses them charges the wrong scheme.
Where to go next
Use the tree as a working tool rather than a diagram: seed the assessment with it, build the analytics program by branch, code the incident history to it, and train from it. The assessment method is in how to run a fraud risk assessment; the purchasing branch is worked through in procurement fraud schemes and the reporting branch in financial statement fraud; what to do in the first two days after a scheme turns out to be real is in the first-48-hours protocol; and the program that ties them together is in the fraud risk management guide.
Related guides
- How to run a fraud risk assessment — the tree as a scenario library
- Fraud risk management and internal audit — prevention, detection and response, with the scheme catalog
- Procurement fraud schemes — bid rigging, kickbacks and phantom vendors in depth
- Financial statement fraud — the five overstatement mechanisms and the cases
- When internal audit finds fraud: the first 48 hours — the response protocol
- Fraud red flags — the behavioural and transactional signals by business cycle
- The CFE for internal auditors — the certification built on this taxonomy
- The accounts payable analytics catalog — billing, payment tampering and vendor schemes as tests
- The payroll analytics catalog — ghost employees and falsified wages as tests
- The journal entry analytics catalog — the financial statement branch as tests
- Procurement fraud analytics — corruption schemes as cross-table tests
- How to audit accounts receivable — skimming and lapping controls
- How to audit inventory — non-cash misappropriation controls
- How to audit payment operations and wire transfers — payment tampering in its electronic form
- All fraud risk guides
Leave a Reply