Think like a thief, investigate like a CFE
Sep 18, 2026
Think Like a Thief: The Skill Every Auditor Needs
Let me be clear before we begin.
I am not suggesting you become a thief.
I am suggesting you learn to think like one.
Because one of the biggest mistakes we make in audit, fraud prevention, compliance, and risk management is looking at a process and asking:
“Are the controls working?”
The thief is asking an entirely different question:
“How do I get around them?”
And that difference matters.
Stop Looking at the Door. Look for the Window.
Auditors tend to approach processes logically.
What is supposed to happen?
Who approves it?
What documentation is required?
What does the policy say?
What does the system allow?
All good questions.
But someone trying to steal from the organization isn't particularly concerned with what is supposed to happen.
They are looking for what can happen.
They notice the door that nobody locks because “only employees come through there.”
They notice that invoices under $5,000 receive less scrutiny.
They notice that nobody really verifies whether a new vendor's bank account belongs to the vendor.
They notice that Mary approves John's expenses and John approves Mary's.
They notice that everyone assumes someone else is checking.
And my personal favorite:
“We've always done it this way.”
To a thief, those words don't sound reassuring.
They sound like an invitation.
Ask the Uncomfortable Question
When I am looking at a process, I like to mentally turn it upside down.
Instead of asking:
“How does this process work?”
Try asking:
“If I wanted to steal from this process, how would I do it?”
Now things get interesting.
If I wanted to submit a fake invoice, what would stop me?
If I wanted to create a fictitious vendor, who would notice?
If I wanted to manipulate a change order, where would I hide the extra cost?
If I wanted to purchase something for myself and charge it to the company, how could I disguise it?
If I wanted to override an approval, could I?
If I wanted to steal $100,000, would it be easier to steal it once or $2,000 fifty times?
That last question is particularly important.
We sometimes build controls to catch the spectacular fraud while leaving dozens of tiny doors cracked open.
The person committing fraud may be perfectly happy walking through those little doors.
Think Beyond the Control
A control can exist and still be useless.
There.
I said it.
A manager's signature on an invoice means very little if the manager signs everything placed in front of them.
A three-way match means very little if someone can manipulate one of the three pieces.
A segregation-of-duties matrix looks wonderful until two people decide to cooperate.
An approval threshold isn't much protection if someone can split a transaction into smaller amounts.
The existence of a control is not the same thing as the effectiveness of a control.
That is where thinking like a thief becomes powerful.
Don't simply identify the obstacle.
Try to defeat it.
Not literally, of course. We're still the good guys.
But mentally attack it.
Follow the Path of Least Resistance
Fraudsters don't necessarily choose the most sophisticated route.
They often choose the easiest one.
That means your greatest vulnerability may not be buried inside some incredibly complicated system.
It may be sitting inside an ordinary process everyone stopped questioning years ago.
A shared password.
A dormant vendor.
An employee who has accumulated too much access.
An approval nobody actually reviews.
A spreadsheet that can be changed without leaving much of a trail.
A supplier whose address happens to match an employee's.
A recurring payment that has quietly become invisible because everyone expects to see it every month.
None of these necessarily means fraud is occurring.
But each deserves a second look.
Try the Thief Test
The next time you review a process, give yourself ten minutes.
Forget the audit program.
Forget last year's workpapers.
Forget the checklist.
Look at the process as though you have one objective:
Get something out of this organization that you aren't entitled to, without getting caught.
Where would you start?
What would you exploit?
Whom would you need?
Which control would worry you?
Which one wouldn't worry you at all?
And perhaps most importantly:
What would you hope the auditor never asks?
There may be your next audit procedure.
Good Auditors Understand Controls. Great Auditors Understand People.
Fraud doesn't happen inside flowcharts.
People commit it.
People find shortcuts.
People make decisions.
People discover loopholes.
People build relationships.
People learn who checks and who doesn't.
People figure out when everyone is busy.
People recognize which explanations make questions disappear.
People see an open window and see opportunity, a just this once moment, an answer to their problems.
Technology changes.
Processes change.
Fraud schemes change.
Human ingenuity?
That one has been remarkably consistent.
So occasionally put down the checklist and look at your organization through a completely different pair of eyes.
Be curious.
Be skeptical.
Be creative.
Be willing to ask the question nobody else thought to ask.
Because sometimes the best way to protect the castle...
is to spend a few minutes figuring out how you would rob it.
Learn it. Grow It. Own It.
Learn and Grow with LG3.
Stay connected with news and updates!
Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.
We hate SPAM. We will never sell your information, for any reason.