1. What Embezzlement Looks Like from an Auditor'S Standpoint
Embezzlement is theft by someone with authorized access. An employee diverts funds, manipulates records, or approves payments to themselves or an associate. Because the person committing it typically has legitimate access to the accounts involved, the activity looks normal until it's examined against specific audit criteria.
In New York, embezzlement is prosecuted under the larceny statutes in Penal Law § 155. The offense ranges from a Class E felony for amounts over $1,000 to a Class B felony when losses exceed $1 million. When the conduct involves programs that receive federal funding, 18 U.S.C. § 666 may apply separately.
Standard audits are not built to catch every instance of corporate embezzlement. They are built to catch material misstatements in financial statements. The distinction matters: an employee who takes $50,000 in small increments over two years may not move any single line item enough to appear in a routine financial statement review.
Red Flags Auditors Look for during Financial Reviews
Auditors reviewing records with fraud risk in mind aren't just running numbers. They're looking for patterns that don't fit normal business activity.
The most common indicators:
- Bank statement and general ledger balances that don't reconcile without explanation
- Transactions entered outside normal business hours, or consistently just under the threshold requiring a second approval
- Disbursements with missing, altered, or identical supporting documents
- Vendor payments to payees not on the approved vendor list, particularly those without verifiable tax records or business addresses
- One employee who both initiates and approves the same transactions
Any single one of these is worth noting. A pattern across several warrants expanded testing.
2. Audit Procedures That Expose Embezzlement
Analytical procedures and variance analysis
Auditors compare financial data across periods: current versus prior year, actual versus budget, one department versus comparable units. A vendor account where payment volume jumped sharply in one quarter without a corresponding change in activity is worth examining. The objective is to find what normal operations can't explain.
Transaction testing
Auditors pull samples of individual transactions and trace them to source documents: purchase orders, approvals, contracts, bank confirmations. In embezzlement cases, this process often turns up payments authorized by the same person who requested them, or transfers to accounts absent from the vendor master file. Altered or fabricated documentation typically surfaces here.
Segregation of duties review
No single employee should control both the initiation and the approval of a financial transaction. When both functions sit with one person, there's no second set of eyes on the money. Auditors map out who handles what and test whether the division holds in practice, not just on paper.
3. How Auditors Evaluate Internal Controls
AICPA AU-C Section 240 requires auditors to assess fraud risk in every financial statement audit. For public companies, Sarbanes-Oxley Section 404 adds a separate requirement to evaluate and attest to the design and operating effectiveness of internal controls over financial reporting.
What auditors test:
| Control area | What auditors examine |
| Authorization | Whether the person initiating a payment is different from the person approving it |
| System access | Whether user permissions in financial systems match actual job responsibilities |
| Reconciliation | Whether account balances are reviewed by someone independent of the preparer |
| Documentation | Whether every disbursement has an attached, verifiable supporting document |
Authorization
- What auditors examineWhether the person initiating a payment is different from the person approving it
System access
- What auditors examineWhether user permissions in financial systems match actual job responsibilities
Reconciliation
- What auditors examineWhether account balances are reviewed by someone independent of the preparer
Documentation
- What auditors examineWhether every disbursement has an attached, verifiable supporting document
A control that exists in the policy manual but isn't followed in practice does not count. Auditors test both design and operation. A gap doesn't prove theft occurred, but it shows where to look next.
4. When a Standard Audit Needs to Become a Forensic Investigation
A financial statement audit gives reasonable assurance that reported figures are materially accurate. That's a different standard from what a fraud investigation requires. When audit findings point toward embezzlement, continuing the standard process is the wrong response.
Escalation makes sense when:
- Unexplained discrepancies persist after the initial inquiry to management
- Anomalies trace back repeatedly to the same employee or department
- There's evidence of altered records, deleted files, or unauthorized system access
- Potential losses reach a level that may require mandatory reporting or law enforcement referral
Forensic accountants work under different professional standards than financial auditors. Their findings have to hold up in litigation or criminal proceedings, which means evidence needs to be preserved with chain of custody documentation from the moment it's identified. Getting legal counsel involved before the forensic engagement begins protects that evidentiary value. For matters that cross into criminal territory, white collar crimes and investigations counsel should be brought in alongside the forensic team from the start.
5. Frequently Asked Questions
Can a routine audit catch embezzlement?
It depends on scope. An audit that includes transaction testing, segregation of duties review, and analytical procedures calibrated to fraud risk can catch it. A narrow audit focused on whether financial statements are materially accurate may not, especially when the amounts don't move reported totals significantly.
What's the difference between a financial audit and a forensic investigation?
A financial audit answers whether the numbers are materially correct. A forensic investigation answers what happened, who did it, and whether there's enough evidence for a legal claim or prosecution. When audit findings raise embezzlement concerns, a forensic engagement needs to follow as a separate process.
How does embezzlement go undetected for years?
Usually because the amounts are small and consistent enough to stay within normal variance ranges. Annual audits don't automatically test individual transactions unless the fraud risk assessment triggers that kind of work. Detection often follows a scope change, a new auditor, or an internal tip.
Who is liable if an audit fails to detect embezzlement?
Under AICPA standards, auditors are responsible for detecting material misstatements due to fraud. If an auditor skipped required procedures and that failure contributed to undetected losses, professional liability or breach of fiduciary duty claims are possible. Whether those claims succeed depends on the specific facts and the scope of the engagement.
If you are dealing with suspected employee theft or an accounting fraud investigation that may lead to litigation, consulting an attorney early can help protect both the evidentiary record and your legal options.
29 Aug, 2025

