The question at hand
Your organization conducts quarterly fraud risk assessments, maintains segregation of duties matrices, and requires dual authorization for payments above defined thresholds. Yet, when fraud occurs, the post-mortem rarely points to a missing control. Instead, it often highlights a culture where employees feel pressured to meet targets, where questioning authority carries career risks, or where management treats compliance as a formality rather than a commitment.
This presents a practical dilemma for stewardship teams and risk professionals: Should you prioritize measurable control frameworks that auditors can verify, or invest in the more challenging task of cultural assessment and remediation? This debate is not merely academic. Resource allocation decisions flow from how you answer it, and those decisions shape your actual fraud exposure.
The case for controls-first governance
Start with what you can measure and enforce. Controls-based fraud prevention rests on a solid foundation: documented procedures, separation of duties, system-enforced approvals, and regular reconciliation. These mechanisms don't depend on employee virtue or managerial tone; they function regardless of cultural health.
From a stewardship perspective, controls offer verifiable assurance. You can test a three-way match requirement, but you can't test whether middle managers feel empowered to speak up. When explaining fraud prevention to institutional investors or preparing for regulatory examination, tangible controls provide concrete evidence of diligence. They create audit trails that demonstrate accountability when something goes wrong.
Controls also scale in ways that cultural interventions struggle to replicate. A well-designed authorization workflow protects the organization whether you have five employees or five thousand. Cultural norms, by contrast, dilute as organizations grow, fragment across geographies, or absorb acquisitions. The finance team in Singapore may operate under entirely different behavioral expectations than the one in Stuttgart, but both can follow the same payment approval protocol.
Risk professionals favoring this approach point to regulatory expectations. Compliance frameworks, from the COSO ERM Framework to sector-specific guidance, emphasize documented controls, not cultural health metrics. When regulators assess your anti-fraud program, they examine your control environment first. Cultural factors enter the discussion only after control deficiencies surface.
The case for culture-first prevention
Controls tell you what happened after the fact. Culture determines whether it happens at all. This perspective holds that fraud prevention begins with the conditions that make fraud thinkable, not the barriers that make it harder to execute.
Consider the control environment itself. Employees with system access can often circumvent technical controls if they're determined to do so, particularly when they understand the control's logic. What stops them isn't the control's elegance but their belief that the organization would respond seriously to the attempt. That belief is cultural, not procedural.
Proponents of culture-first prevention argue that control frameworks create compliance without commitment. Employees follow procedures to avoid consequences, not because they've internalized the principles behind them. This produces brittle fraud prevention: effective until pressure mounts, targets seem unreachable, or leadership signals that results matter more than methods.
The cultural red flags that precede fraud are observable if you know where to look. Does your organization celebrate employees who "get creative" to hit quarterly numbers? Do managers respond to internal audit findings with defensiveness rather than curiosity? When employees raise concerns about aggressive accounting or customer treatment, do those concerns receive serious investigation or quietly damage the reporter's career prospects? These patterns predict fraud risk more reliably than control documentation quality.
From a stewardship standpoint, cultural assessment addresses root causes rather than symptoms. If your organization experiences repeated control failures across different functions, the common factor isn't the controls themselves but the environment that tolerates their circumvention. Fixing culture fixes multiple fraud vectors simultaneously. Fixing controls addresses them one at a time.
Where practitioners actually land
Most risk professionals don't choose between these approaches cleanly. They implement controls because they must, then layer cultural initiatives on top when budget and leadership attention permit. This produces predictable patterns: robust control documentation coupled with employee surveys that reveal troubling attitudes about ethical shortcuts, or comprehensive fraud policies that employees can recite but don't actually believe management would enforce.
The practical challenge is measurement asymmetry. You can quantify control coverage, testing frequency, and remediation timelines. Cultural health resists the same precision. This creates reporting problems when communicating with boards or investors who expect metrics. Saying "we've closed 94% of identified control gaps" sounds more credible than "we've improved psychological safety in the finance function," even if the latter matters more for fraud prevention.
Organizations with mature fraud prevention programs often use controls as the foundation but treat cultural indicators as leading metrics. They track employee turnover in control functions, analyze patterns in whistleblower reports, monitor whether managers retaliate against those who slow processes to verify compliance, and measure how quickly leadership responds to ethical concerns versus operational ones.
Our take
Controls without culture create the appearance of fraud prevention while leaving fundamental vulnerabilities unaddressed. Culture without controls creates good intentions that lack enforcement mechanisms. You need both, but the sequencing matters.
Build your control framework first because it's non-negotiable and because it creates the baseline from which you can identify cultural problems. When controls fail repeatedly in similar ways across different business units, you're seeing cultural issues manifest. When employees find creative workarounds to required procedures, you're learning what your culture actually values versus what it claims to value.
Then invest in culture deliberately, not as a soft complement to "real" controls but as the mechanism that determines whether controls function as designed or get gamed into irrelevance. This means leadership accountability for tone, consequences for managers who pressure employees to circumvent controls, and genuine protection for those who raise concerns.
For stewardship teams evaluating fraud risk, examine both. Ask management to explain their control framework, then ask employees whether they believe management would support them for slowing a deal to verify compliance. The gap between those answers tells you more about actual fraud exposure than the control documentation alone ever could.



