Top
August 7, 2026

Internal Fraud Costs More Than FIs Realize

Fragmented ownership, resource constraints and limited information sharing may leave insider fraud activity undetected while obscuring the value of stronger controls.

Financial institutions often devote more resources to external fraud than to internal fraud. The rationale is reasonable: external attacks typically generate larger, more visible losses. Fewer resources and fragmented attribution methods, however, may lead to undercounted internal fraud, providing an incomplete view of insider risk.

There is a structural problem in how some institutions measure internal fraud, according to Michael Callahan, director of the Auriemma Roundtables Internal Fraud Roundtable. The detection and investigation of insider fraud may be split among fraud, human resources, employee relations, corporate security and compliance, each with separate case management and reporting processes. When those functions do not consistently share case outcomes and associated costs, incidents investigated as employee misconduct may never enter centralized fraud reporting. Internal fraud can therefore appear less costly than it is, leaving fraud leaders with an incomplete view of their exposure and the potential return from stronger controls.

A lack of investment in internal fraud monitoring can result in fewer detected cases, reinforcing the perception that such fraud is limited. Meanwhile, increasingly sophisticated external fraud rings are recruiting employees to help access accounts, expose sensitive information, bypass controls, or identify potential targets.

The result is a detection gap with financial, regulatory and reputational consequences.

What Institutions Cannot Measure, They Struggle to Fund

Reported internal fraud losses may be substantially lower than actual losses because responsibility is often divided across detection, investigation and reporting.

A fraud or monitoring team may identify suspicious employee activity, while HR, employee relations or corporate security investigates the case and determines the outcome. If findings and associated costs do not flow back into centralized fraud reporting, confirmed incidents may be classified only as employee misconduct. Separate case management systems, reporting practices and loss categories can prevent leaders from seeing the institution’s total internal threat exposure.

Fragmented reporting also makes it harder to demonstrate the ROI of internal fraud programs. When institutions consider only direct internal fraud losses prevented or recovered, they may overlook savings from detecting employee-enabled external fraud and reducing investigation costs, staff time, customer remediation, legal expenses and reputational harm. A broader accounting provides a clearer picture of the financial value that stronger prevention and detection can deliver.

Stronger measurement begins with understanding where cases are managed, how they are classified, and which costs are included. Without that baseline, a low loss figure can say as much about an institution’s detection program as it does about the level of internal fraud occurring.

One Alert Rarely Tells the Whole Story

Internal fraud detection frequently depends on connecting several activities that may appear inconclusive on their own.

In a recent Auriemma Roundtables poll of internal fraud leaders, unusually frequent account access was the most commonly cited signal that an employee may be accessing customer accounts inappropriately. Frequency becomes more meaningful when it is evaluated alongside the reason for the access and what happens in the account afterward.

“Fraud is rarely uncovered through a single alert,” said Callahan. “The stronger cases come from connecting activity. An employee may access an account without a business need, return to it repeatedly, or view sensitive information. If suspicious transactions follow, investigators have a much clearer pattern to examine.”

Alert strategies should therefore connect employee behavior with account and transaction activity. An employee viewing a family member’s account may raise an access concern. Repeated access followed by fraudulent transactions creates a stronger investigative lead.

The Office of the Comptroller of the Currency similarly recommends combining preventive and detective controls. Its fraud risk management guidance identifies employee account monitoring, system access patterns, and overrides among the tools institutions can use to detect suspicious activity. The agency also notes that collusion and the circumvention of controls can allow fraud to occur even within a strong governance structure.

Internal Controls Can Also Expose External Fraud

The distinction between internal and external fraud is becoming less clear as outside fraudsters recruit employees inside financial institutions.

According to Auriemma Roundtables survey data, 60% of internal fraud leaders said their institutions had identified cases in which external fraudsters recruited employees to facilitate fraud. The finding underscores the overlap between internal and external fraud and the value of monitoring employee activity as part of a broader fraud strategy.

Frontline employees – most often branch employees, but also contact center agents – can be particularly attractive targets because of their access to customer information and account servicing capabilities. An employee recruited by external fraudsters may be asked to provide sensitive data, identify vulnerable accounts, perform unauthorized account maintenance or help an outside actor work around established controls.

Some institutions are conducting retrospective reviews of external fraud events to determine whether an employee accessed the affected accounts before the fraud occurred. Those investigations can reveal how an external attack succeeded and whether other accounts remain at risk.

“When internal and external fraud are investigated separately, institutions can miss an important connection,” Callahan said. “A strong internal fraud program can uncover the employee activity behind an external attack, help identify the broader scheme and improve the institution’s chances of containing additional losses.”

Part of the ROI from internal fraud controls may therefore appear in the external fraud ledger. Preventing employee misconduct is one benefit. Detecting and recovering losses connected to a larger outside scheme can create additional returns.

The Exposure Extends Beyond Direct Losses

Internal fraud carries regulatory and reputational exposure alongside direct financial loss.

OCC guidance calls on FIs to maintain systems that identify, measure, monitor and control fraud risk. The OCC’s Insider Activities handbook warns that weak systems and controls can increase operational risk from insider abuse and fraud. The OCC also notes that real or perceived insider misconduct can undermine confidence among customers, shareholders and business partners.

The consequences of control failures can be significant. Recent OCC actions have included multimillion-dollar penalties tied to systemic weaknesses in risk management and internal controls. The agency has also held former executives personally accountable for failures involving controls, audit activity and the escalation of widespread employee misconduct. These actions addressed broader risk-management shortcomings, but they illustrate how gaps in employee oversight can become a serious supervisory concern.

The reputational impact may prove even harder to contain: Customers may view employee misconduct as particularly egregious because the institution trusted that individual with direct access to customer accounts and information.

Peer Exchange Can Help Internal Fraud Programs Catch Up

To best prevent insider fraud events and establish ROI of controls, Internal fraud teams need comparable opportunities to benchmark their programs.

Auriemma Roundtables’ Internal Fraud Roundtable provides a forum for financial institution leaders to compare controls, investigative strategies and emerging threats. Members also benchmark program structure, staffing and performance against peers, helping internal fraud teams identify gaps faster, improve measurement and build a stronger case for investment.

Contact Zeenat Shah to learn more about membership.

You are now leaving the Auriemma Roundtables website and being redirected to Auriemma Group.

Go Back Continue