Internal collusion isn’t one fraud pattern — it’s a family of them, unified by the same underlying mechanic: two or more people, at least one inside the business, working together to make a fraudulent transaction look routine. Recognising the different forms it takes is the first step to building controls that catch more than one of them.
Common forms
- Procurement fraud — an employee steers business to a favoured supplier in exchange for kickbacks, inflating prices or waving through inflated invoices.
- Billing and invoicing schemes — fake invoices for goods or services never delivered, approved by someone who benefits from the payment going through.
- Asset misappropriation — inventory, equipment, or funds diverted with the help of falsified records that would otherwise flag the discrepancy.
- Expense fraud — personal costs disguised as business expenses, approved without genuine scrutiny.
- Payroll fraud — ghost employees, inflated salaries, or unauthorised bonuses pushed through by someone with access to the payroll system.
Why these schemes are hard to catch
Every one of these relies on the same weakness: a control that assumes the people on either side of it are acting independently. Segregation of duties works when the person raising a transaction and the person approving it have no reason to cooperate. It breaks down the moment they do — because each individual action still passes review on its own.
Building defenses that account for this
- Genuine segregation of duties. Not just different job titles, but no overlap in the people who can create, approve, and reconcile the same transaction.
- Regular, pattern-focused audits. Reviews that look for the same supplier repeatedly clearing just under an approval threshold, or spending that clusters around specific approvers.
- Data-driven monitoring. Collusion usually requires connecting records across systems — HR, procurement, payments — that don’t naturally talk to each other. That’s exactly the kind of cross-referencing worth automating.
- A real whistleblower channel. Many collusion cases surface because a colleague noticed something and had a safe way to say so.
- Independent supplier verification. A supplier’s registration, ownership, and banking details checked against external sources, not just internal records that a colluding employee may have supplied.
Final thought
No single control catches every form of internal collusion, because the schemes themselves take too many shapes. The businesses that manage this risk well combine structural controls — segregation of duties, independent verification — with active monitoring that looks for the patterns collusion tends to leave behind.
