HomeOur Blog
Blog Posts

What Is Fraud?

Above Security Team

Above Security Team

Table of contents
Above Security Team

Above Security Team

When the news reports insider fraud, it tells vast stories of leadership and boards of directors who hold secret information about their company that allows them to trade stocks before announcements so that they can make or save millions of dollars. Realistically, most insider fraud consists of many insignificant transactions that appear normal when no context around intent exists. 

Identifying fraud can be complicated. Individual signals may not trigger an alert and rarely explain why someone took an action. Understanding fraud means that the different teams involved in receiving alerts, investigating employee activities, and providing consequences have shared evidence about the event and can understand why it occurred. 

What is fraud?

Fraud is when a person or organization intentionally devices others by misrepresenting or concealing information with the goal of obtaining money, property, services, or other benefits. Unlike an error or accidental policy violation, fraud involves intent, so the person committing the act knows it is wrong and uses deception for their own benefit or to cause a loss for another party. 

Fraud can occur inside and outside an organization. Insider fraud might be an employee submitting falsified invoices or expense reports, while external fraud looks like using stolen personal information to commit identity theft or financial fraud. While the specific conduct varies, determining whether a suspicious activity constitutes fraud requires understanding the context around the event, like circumstances or intent.

What are the elements of fraud?

While the legal requirements for proving fraud in a court may change by jurisdiction, fraud typically involves several common elements:

  • Misrepretentation or omission: Someone makes a false statement, hides information, or keeps out facts that change how someone else understands a situation. 
  • Knowledge: The person committing fraud knows that the representation is false or acts with reckless disregard for the truth. 
  • Intent: The deception seeks to influence someone else’s actions or decisions.
  • Reliance:Someone else reasonably relies on false or misleading information. 
  • Harm: The reliance results in a loss, injury, or other form of damage. 

Every fraud claim revolves around an action and an intent. While your tools may help you identify an unusual transaction or altered electronic files, investigators still need to understand the fraud perpetrator's intent when taking action.

Why does fraud happen?

People commit fraud for many reasons. However researchers and fraud examiners typically explain the conditions as the Fraud Triangle, the context that makes fraudulent behavior more likely. The model focuses on the three factors of pressure, opportunity, and rationalization.

How does the Fraud Triangle work?

The Fraud Triangle describes the three common conditions associated occupational fraud:

  • Pressure: A financial, professional, or personal incentive that motivates someone to perpetrate fraud. 
  • Opportunity: Weak internal controls, excessive access privileges, inadequate oversight, or other gaps that make committing and potentially concealing fraud easier.
  • Rationalization: Justification for the behavior, like the fraudster believing they deserve the money, will eventually repay it, or view it as recompense for unfair treatment. 

Employee expense fraud

A common example of insider fraud is an employee who submits falsified travel expense reports and receipts to receive reimbursement for expenses they never incurred:

  • Pressure: The employee struggles with unexpected personal expenses and needs money.
  • Opportunity: Weak internal controls allow employees to submit expenses without requiring adequate receipt or transaction verification. 
  • Rationalization: The employee believes the company underpays them and views the fraudulent reimbursements as compensation owed.

AI agent-enabled procurement fraud

An employee manipulates a procurement AI agent to substitute a vendor that the employee secretly owns as a replacement for the organization’s preferred supplier. Since the organization authorized the agent to make supplier substitutions, the resulting purchase order initially appears legitimate. In reality, the AI agent acts on behalf of the employee committing fraud. In this case, the Fraud Triangle looks like this:

  • Pressure: The employee wants income or currently experiences financial hardship.
  • Opportunity: The agent has legitimate authority to substitute suppliers while insufficient governance prevents the organization from identifying the employee’s influence over the agent while the employee conceals their ownership of the replacement vendor. 
  • Rationalization: The employee believes that their company supplies products of equal quality, meets the organization’s requirements, and charges a competitive price, so the organization receives the same value it would have from another supplier.

What are the different types of fraud?

Fraud can happen from inside or outside an organization and take many different forms. 

External fraud schemes typically seeks to steal money, credentials, personal information, or payment information and can include: 

  • Phishing scams
  • Romance scams
  • Online shopping scams
  • Investment scams
  • Ponzi schemes

For many businesses, fraud involving trusted users and legitimate business systems can be difficult to identify because the activity initially appears authorized.

What is occupational fraud?

Sometimes called insider fraud, these activities occur when a trusted insider deliberately misuses their position for personal benefit. When an employee, contractors, executive, or other person already has legitimate system, data, and business process access, then the fraudulent actions can resemble normal work activity. 

Occupational fraud can include:

  •  Asset misappropriation: Theft or misuse of an organization’s money or other assets, including skimming cash receipts, misusing procurement cards, submitting falsified invoices or travel expense reports, and stealing intellectual property.
  • Corruption: Abuse of an employee’s position or influence for personal benefit, including conflicts of interest, bribery, bid rigging, or manipulating purchase orders to favor a particular vendor.
  • Financial statement fraud: Intentional misrepresentation or omission of financial information to make an organization’s financial performance or position appear different from reality.

While internal controls can reduce a trusted insider’s opportunities to perpetrate occupational fraud, investigators typically need information from multiple systems to distinguish authorized business activity from deliberate misuse.

How can technology enable fraud?

Technology enables traditional and emerging forms of fraud by increasing the number of systems and identities that can participate in a transaction. To execute or conceal fraud, an insider might use:

  • Remote access
  • Electronic files
  • Financial applications
  • Social engineering

Artificial intelligence (AI) complicates detection further because AI agents can perform actions on behalf of human users. While an AI agent does not intrinsically possess fraudulent intent, the person directing or manipulating it may use the agent to further a fraudulent scheme. When investigating fraud that uses AI agents, investigators need to determine:

  • Which identity performed an action.
  • Who caused the action.
  • What authority was delegated.
  • What context surrounded the action.

What are the warning signs of fraud?

Fraud is often difficult to detect because the individual actions may have legitimate explanations. The real challenge is extracting the fraudster’s intent based on context that can include information from human resources (HR) or external personal challenges. 

Common warning signs of potential fraud include:

  • Unusual financial activity: Unexpected payments, duplicate or altered invoices, unusual refunds, changes to purchase orders, or transactions involving unfamiliar vendors.
  • Abnormal account behavior: Logins from unexpected locations, unusual remote access, changes in access patterns, or use of systems and data outside an employee’s normal responsibilities.
  • Attempts to bypass internal controls: Circumventing approval processes, segregation of duties, spending limits, or other controls intended to prevent unauthorized use.
  • Unusual data activity: Accessing, downloading, modifying, or transferring electronic files or sensitive information in ways inconsistent with normal business activities.
  • Changes in communication or relationships: Undisclosed vendor relationships, unusual communications with third parties, or other activity that provides context for otherwise legitimate transactions.

How do organizations detect and investigate fraud?

Fraud detection alerts the organization to activities that might require an investigation. However, the investigation provides documentation and evidence around:

  • What happened
  • Who was involved
  • Whether the data supports an intentional deception

Effective fraud investigations may require organizations to correlate information from multiple sources, including:

  • Identity and access data: Identifies the human, service account, or AI agent associated with an activity and the permissions available to that identity.
  • Financial and transaction data: Documents payments, purchase orders, invoices, procurement activity, account changes, and other financial events involved in the suspected scheme.
  • Endpoint and application activity: Shows how users interacted with electronic files, applications, devices, and other organizational resources.
  • Communications: Provides context from email, messaging platforms, and other collaboration tools that may help establish relationships or explain actions.
  • AI agent activity: Connects actions performed by AI agents to the human users, instructions, delegated authority, tools, and systems involved.

Investigators often struggle to correlate this evidence and reconstruct the timeline when they have to evaluate each event in isolation. Returning to the manipulated AI agent example, the AI legitimately substituted one vendor for another, according to the purchase order. Investigators need evidence connecting the fraudster to the agent’s instruction to determine whether the transaction was part of a fraudulent scheme.

The core challenge that investigators face is that detecting an action is fundamentally different from establishing intent. Organizations need context to move from what happened and who caused it to why it happened and whether the evidence supports a finding of fraud.

What questions do investigators need to ask when trying to establish intent?

Intent focuses on understanding why someone would engage in a fraudulent act. When trying to correlate the various data points, investigators can focus on the following questions:

  • Knowledge: What did the person know before the suspicious activity occurred?
  • Authorization: What was the person or AI agent authorized to do, and how was that authority used?
  • Direction and delegation: Did the person instruct another user, system, or AI agent to perform an action on their behalf?
  • Sequence: What actions occurred before, during, and after the suspected fraud?
  • Relationships: Did the person have undisclosed connections to vendors, accounts, third parties, or other participants?
  • Personal benefit: Did the person stand to gain financially or receive another benefit from the activity?
  • Misrepresentation: Did the person provide false information, omit material facts, or create misleading records?
  • Concealment: Did the person alter records, delete electronic files, circumvent internal controls, or otherwise attempt to hide the activity?

Above Security

tl;dr: Above turns scattered telemetry into defensible stories of intent, not just isolated events.

Above is an insider risk management platform built around narrative intelligence. Above's AI agents continuously observe how employees and their AI agents interact with data, apps, and AI tools to determine intent and intervene when a risky action is about to occur. Those signals get stitched into clear timelines that explain what happened, why it happened, and how risk evolved over time. 

With in-the-moment coaching, and automatically produced investigation-ready narratives that security, legal, and HR can actually use.

‍

Share

Contact us

You've made a great move.
We'll be in touch shortly

Close
Watch Now