Why small and medium businesses are especially exposed
Fraud does not discriminate by size. In fact, smaller businesses can be more vulnerable because trust is often concentrated in a few key people, financial controls may be informal, and there is rarely a dedicated security or compliance team to spot anomalies. When a business has thirty employees rather than three thousand, everyone knows everyone. That closeness is a strength, but it can also make it harder to challenge a colleague or question a payment request. The result is a narrow window between suspecting something is wrong and needing to act. You must move quickly, but not so quickly that you compromise fairness or break the law. This article walks through a practical, balanced approach.
Spot the red flags before they become a crisis
Most fraud in small firms is internal – committed by someone with access to money, stock, data or purchasing. The red flags are often behavioural, procedural or financial. Look for patterns rather than one-off mistakes.
- Unusual payment activity: supplier invoices with slightly altered bank details, payments just below approval thresholds, or duplicate payments to the same reference.
- Expense oddities: receipts that look altered or repeated, claims for travel that clash with the staff rota, or expenses submitted by someone who never travels.
- Inventory and asset gaps: stock levels that do not match the sales ledger, unexplained write-offs, or equipment that disappears.
- Behavioural changes: a normally collaborative colleague becoming defensive about their work, refusing to take annual leave, or insisting on handling a particular supplier alone.
- Control bypasses: one person reconciling the bank account and approving payments, or a manager who overrides purchase orders without explanation.
Keep a confidential log of anything that concerns you. Write down dates, times, amounts and who was involved. This log will be invaluable if you later need to involve a specialist or the police.
Isolate the affected records straight away
Once you have reasonable grounds to suspect fraud, your first practical step is to prevent further loss and preserve evidence. Do not confront the suspect yet. Instead, quietly isolate the records and systems involved.
- Freeze access: suspend the individual’s ability to approve payments, access bank accounts, or alter supplier details. Do this discreetly, perhaps by asking IT to reset permissions during a routine maintenance window.
- Preserve digital evidence: export relevant emails, system logs, and financial transactions to a secure, read-only location. Do not rely on screenshots – they are easy to challenge later.
- Secure physical documents: collect invoices, expense claims, delivery notes and bank statements. Keep them in a locked cabinet with a clear chain-of-custody log.
- Back up before you investigate: if you need to examine a suspect’s laptop or phone, take a forensic image first. Simply opening files can change metadata.
The aim is to stop the bleeding without tipping off the person involved. Loose lips in a small office can destroy evidence in minutes.
Balance speed with fairness and legal compliance
Small firms often feel they must act instantly. But a rushed, unfair process can expose you to claims of unfair dismissal, breach of contract, or data protection breaches. Speed matters, but fairness matters just as much.
First, check your own policies. Do you have a disciplinary procedure that covers investigation? If not, follow the Acas Code of Practice on disciplinary and grievance procedures – it applies to all employers, regardless of size. Key steps include:
- Act consistently: treat the suspected fraud like any other gross misconduct allegation. Do not single someone out because of personal dislike.
- Give the person a chance to respond: before making a final decision, hold an investigatory meeting. The employee has the right to be accompanied by a colleague or trade union representative.
- Respect data protection: only access personal data that is relevant to the investigation. Do not trawl through private emails or messages without a lawful basis. Keep records secure and retain them only as long as necessary.
- Avoid unlawful surveillance: covert monitoring of employees is strictly regulated. You cannot simply install key-logging software or track a suspect’s car without a strong legal justification and, often, a policy that employees know about.
If the fraud involves theft or false accounting, you may need to report it to the police. But remember: a criminal investigation runs alongside, not instead of, your internal process. Do not promise the police that you will not take disciplinary action, and do not let a slow police response stall your own reasonable steps.
Bring in specialists when the stakes are high
You do not need a forensic accountant for every missing £50. But for larger sums, complex accounting trails, or suspected collusion, specialists save time and reduce risk. A fraud investigator or forensic accountant can trace funds, interview witnesses properly, and produce a report that stands up to scrutiny. An employment lawyer can advise on the disciplinary process or help you avoid a tribunal claim. A digital forensics expert can recover deleted files and confirm whether evidence has been tampered with.
When choosing a specialist, ask for relevant experience in small business fraud, not just corporate cases. And involve them early – before you have conducted interviews or moved data around. Their advice on evidence handling can be the difference between a successful recovery and a lost case.
Learn from the investigation and tighten controls
Once the immediate issue is resolved, take time to understand how the fraud happened. Was it a lack of segregation of duties? A culture where nobody questioned the boss? Update your financial controls: require two signatures above a certain amount, rotate who reconciles the bank account, and run surprise audits. Train staff to recognise red flags and give them a confidential way to report concerns. Most importantly, do not let fear of another fraud make you distrust everyone. The goal is robust, fair processes that protect your business and your team.

Comments