Trust is not a control
Aug 24, 2026
The Fraudster Didn’t Beat Your Controls. Your Culture Helped Them.
Meet Bob.
Everyone loves Bob.
Bob has worked here for 23 years. Bob knows everyone. Bob knows where everything is. Bob trained half the department. He remembers when the accounting system was installed, knows which reports nobody reads, and knows exactly which manager will approve something without looking too closely because she is usually trying to eat lunch, answer three emails and join a Teams meeting at the same time.
Bob is dependable.
Bob is loyal.
Bob is trusted.
Bob would never steal from the company.
Until Bob steals $3.7 million.
And suddenly everyone is sitting around the conference table saying the same thing:
“But Bob was the last person I would ever suspect.”
Exactly.
That may have been part of the problem.
When Trust Quietly Becomes a Control
Trust is important. Organizations couldn't function without it.
But somewhere along the way, trust can quietly become a substitute for controls.
"Bob doesn't need a second approval."
"She's the CFO."
"He's been handling that account forever."
"We know that vendor."
"She's one of our best employees."
None of those statements is a control.
Yet listen carefully inside many organizations and you'll hear them used as though they are.
Controls gradually become something we apply to other people.
New employees.
Junior employees.
Unknown vendors.
People who make us nervous.
Meanwhile, the people we know, like and trust receive little unofficial exemptions.
Not because anyone deliberately dismantled the control environment.
Because we're human.
And humans are wonderfully complicated creatures.
Fraudsters Don't Always Beat Controls
When we imagine fraud, we often picture someone cleverly circumventing sophisticated systems.
They hacked the software.
They forged the approval.
They manipulated the documentation.
They found a brilliant loophole nobody else noticed.
Sometimes.
But sometimes the fraudster doesn't need to defeat the control at all.
Someone defeats it for them.
"Can you approve this quickly?"
Sure.
"I forgot my access card. Can you let me through?"
Of course.
"I'm traveling and can't get into the system. Can you process this for me?"
No problem.
"Don't worry about the documentation. I'll send it tomorrow."
Okay.
And there it is.
Not some elaborate Ocean's Eleven operation involving lasers, acrobatics and George Clooney.
Just someone being helpful.
The Most Dangerous Four Words in Fraud?
“I know this person.”
Knowing someone feels like evidence.
It isn't.
You may know someone professionally for twenty years without knowing what is happening in their life today.
Financial pressure.
Addiction.
Family problems.
Resentment.
Debt.
A belief that they're underpaid.
A belief that they're simply “borrowing” the money.
Or perhaps nothing dramatic happened at all.
They noticed an opportunity.
They tried something small.
Nobody noticed.
So they tried it again.
Fraud doesn't always begin with someone deciding:
“Today I shall steal $3.7 million.”
It can begin with $500.
Then $2,000.
Then $10,000.
And eventually the fraud becomes part of the process.
Then Comes Authority
Now replace Bob with Barbara.
Barbara is the CFO.
Barbara doesn't like being questioned.
Everyone knows this.
When Barbara asks for something, people move.
When Barbara asks why something hasn't been paid, it gets paid.
When Barbara says, “I'll approve it later,” people nod.
Technically, the organization has controls.
Practically, the organization has Barbara.
This is where culture starts eating the control environment for breakfast.
A policy may say that every transaction requires appropriate authorization.
Culture may say:
“Do not annoy Barbara.”
Guess which one wins at 4:47 on a Friday afternoon?
This isn't necessarily because Barbara is committing fraud.
She may be completely honest.
But if employees learn that challenging senior people carries a social or professional cost, you've created something potentially more dangerous than one bad transaction.
You've created a culture where authority can override skepticism.
And fraud loves that.
Urgency: Fraud's Favorite Little Helper
Then there is urgency.
Fraud and urgency have always been good friends.
"We need this paid today."
"The deal will collapse."
"The supplier is threatening to stop work."
"The CEO is waiting."
"I'll explain later."
Urgency is powerful because it changes the question.
Instead of asking:
“Should we do this?”
people start asking:
“How quickly can we do this?”
The control hasn't disappeared.
The mindset has.
And once speed becomes more important than verification, fraud has found itself a rather comfortable chair.
The Employee Who Didn't Want to Make a Fuss
This one bothers me perhaps more than anything else.
After fraud is discovered, investigators sometimes hear:
"I thought it was strange."
"Something didn't seem right."
"I noticed that months ago."
"I nearly reported it."
Nearly.
Why didn't they?
Sometimes they feared retaliation.
Sometimes the person involved was senior.
Sometimes they weren't sure enough.
Sometimes they didn't want to accuse someone unfairly.
And sometimes they simply didn't want to be that person.
The difficult one.
The suspicious one.
The employee who asks too many questions.
That is a culture problem.
Because your fraud hotline can be technically flawless.
Your whistleblower policy can be beautifully written.
Your Code of Conduct can have lovely graphics.
But if employees believe speaking up will damage their careers, your reporting mechanism isn't working.
It's decorating the intranet.
Controls Live in Culture
This is the part we sometimes miss when auditing fraud risk.
We test whether the control exists.
Good.
We test whether it operated.
Better.
But do we test whether people actually believe in it?
That's different.
Imagine a policy requiring independent approval for vendor bank account changes.
The control exists.
The procedure is documented.
Your sample of 25 transactions looks beautiful.
Tick.
Tick.
Tick.
Now sit with the Accounts Payable team and ask:
“What happens if a senior executive tells you to skip this because the payment is urgent?”
That answer may tell you more about the control environment than the 25 transactions did.
Beware the Untouchables
Every organization seems to have them.
The superstar salesperson.
The brilliant engineer.
The executive who delivers results.
The employee who has been there forever.
The founder's favorite.
The person who “knows where all the bodies are buried.”
Sometimes organizations tolerate behavior from high performers that would never be accepted from anyone else.
Controls become flexible.
Expenses aren't questioned.
Documentation arrives late.
Approvals become informal.
People stop challenging unusual behavior because:
“That's just how they are.”
And perhaps that's exactly how they are.
But here's the problem.
Fraud doesn't care how valuable someone is to the organization.
In fact, the more trusted, powerful and knowledgeable someone becomes, the greater their potential ability to circumvent controls.
Trust shouldn't eliminate controls.
Sometimes trust is exactly why controls matter.
Audit the Exceptions
Want an interesting fraud audit?
Don't start with the transactions that followed the process perfectly.
Start with the exceptions.
Who gets to bypass normal procedures?
Whose expenses are rarely challenged?
Who can request and approve?
Which vendors receive special treatment?
Which employees have access that nobody remembers granting?
Where do people say:
"Normally we do X, but for this person we do Y."
There is your trail.
Exceptions aren't automatically fraud.
But exceptions tell you where the organization has decided that the rules are negotiable.
And that's worth understanding.
Ask the Question Nobody Likes
Here's a wonderfully uncomfortable exercise for management teams, auditors and fraud professionals.
Ask:
“Who in this organization would we have the hardest time believing could commit fraud?”
Write down the names.
Congratulations.
You've just created a fascinating fraud risk assessment.
Not because those people are dishonest.
Quite the opposite.
They're the people the organization trusts so completely that colleagues may have stopped noticing when normal controls don't apply.
Culture Can Be Your Strongest Fraud Control
There is good news.
Culture can create fraud risk.
But culture can also become one of your strongest fraud controls.
Imagine an organization where employees comfortably say:
"I know you're the CFO, but I still need the second approval."
And the CFO replies:
"Absolutely."
Imagine managers thanking employees for questioning unusual transactions.
Imagine executives following the same expense rules as everyone else.
Imagine employees knowing that reporting something suspicious doesn't mean accusing someone of fraud. It means raising a concern worth examining.
Imagine hearing this:
“We trust people. That's why we have controls.”
Now we're getting somewhere.
Because good controls don't exist because everyone is dishonest.
They exist because organizations are run by humans.
Humans make mistakes.
Humans experience pressure.
Humans rationalize things.
Humans sometimes make terrible decisions.
And yes, occasionally humans named Bob steal $3.7 million.
Your Next Fraud Audit Might Not Start With a Transaction
It might start with a conversation.
Ask employees:
“Which controls are people afraid to enforce?”
Ask:
“Who can override the rules?”
Ask:
“What happens when someone challenges a senior executive?”
Ask:
“Which employees or vendors do we trust enough that we rarely question them?”
And perhaps most importantly:
“If you saw something that didn't feel right tomorrow, would you genuinely feel comfortable saying something?”
Then stop talking.
Listen.
Because sometimes the biggest fraud weakness isn't buried in your ERP system.
It isn't hiding in an invoice.
It isn't lurking in your access logs.
It's sitting quietly in the organization's culture, surrounded by perfectly good controls that everybody has somehow agreed don't always need to be followed.
The fraudster didn't beat your controls.
Your culture helped them.
And somewhere, Bob is hoping nobody notices.
LG3 helps professionals turn complicated risks into practical questions they can actually use. Because sometimes managing risk starts with having the courage to ask the uncomfortable question.
Stay connected with news and updates!
Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.
We hate SPAM. We will never sell your information, for any reason.