Collusion
Collusion is a secret agreement or cooperation between two or more parties, typically for an illegal or deceitful purpose such as cheating, misleading, or defrauding others. In a governance context, it often involves individuals working together to bypass controls or gain an improper advantage. Because it is deliberately concealed, collusion is generally difficult to detect through routine oversight.
Collusion refers to a deceitful or secret agreement between two or more parties to defraud a third party of their rights, limit open competition, or accomplish an otherwise illegal or improper purpose. In internal control terms, collusion is a recognized inherent limitation of any control system: because segregation of duties and other controls generally assume parties act independently, coordinated action among two or more individuals can circumvent controls that would otherwise function as designed. It is typically distinguished from unilateral misconduct in that it requires concerted, concealed cooperation, and its detection often depends on factors beyond standard control testing, such as investigation, whistleblowing, or data analytics. The specific legal treatment and consequences of collusion vary by jurisdiction, sector, and the underlying conduct involved; this entry is educational and not legal, audit, or compliance advice.
Why it matters
Collusion strikes at one of the core assumptions underpinning most internal control systems. Controls such as segregation of duties, dual authorization, and independent review are generally designed on the premise that individuals act independently, so that no single person can both perpetrate and conceal an improper act. When two or more parties secretly agree to coordinate their actions, they can circumvent controls that would otherwise function as designed. For this reason, collusion is widely recognized as an inherent limitation of any control framework rather than a defect that better control design alone can fully eliminate.
Because collusion is deliberately concealed and involves cooperation among parties, it is generally difficult to detect through routine oversight and standard control testing. A control may be well designed and operating effectively as tested, yet still be defeated by coordinated action among the very people expected to provide independent checks on one another. This gap has significant implications for how boards, management, and assurance functions think about detection: reliance on preventive controls alone is typically insufficient, and detection often depends on other mechanisms such as investigation, whistleblowing channels, and data analytics.
The legal treatment and consequences of collusion vary considerably by jurisdiction, sector, and the nature of the underlying conduct, whether that involves fraud, anti-competitive arrangements, or other improper purposes. Organizations therefore generally treat collusion both as a compliance risk requiring appropriate policies and reporting channels, and as a limitation to be acknowledged when management represents on, and assurance functions opine on, the effectiveness of internal controls. This entry is educational and not legal, audit, or compliance advice.
Who it's relevant to
Inside Collusion
Common questions
Answers to the questions practitioners most commonly ask about Collusion.