Skip to main content
Category: Fraud Risk Management

Collusion

Also known as: Secret agreement, Collusive arrangement
Simply put

Collusion is a secret agreement or cooperation between two or more parties, typically for an illegal or deceitful purpose such as cheating, misleading, or defrauding others. In a governance context, it often involves individuals working together to bypass controls or gain an improper advantage. Because it is deliberately concealed, collusion is generally difficult to detect through routine oversight.

Formal definition

Collusion refers to a deceitful or secret agreement between two or more parties to defraud a third party of their rights, limit open competition, or accomplish an otherwise illegal or improper purpose. In internal control terms, collusion is a recognized inherent limitation of any control system: because segregation of duties and other controls generally assume parties act independently, coordinated action among two or more individuals can circumvent controls that would otherwise function as designed. It is typically distinguished from unilateral misconduct in that it requires concerted, concealed cooperation, and its detection often depends on factors beyond standard control testing, such as investigation, whistleblowing, or data analytics. The specific legal treatment and consequences of collusion vary by jurisdiction, sector, and the underlying conduct involved; this entry is educational and not legal, audit, or compliance advice.

Why it matters

Collusion strikes at one of the core assumptions underpinning most internal control systems. Controls such as segregation of duties, dual authorization, and independent review are generally designed on the premise that individuals act independently, so that no single person can both perpetrate and conceal an improper act. When two or more parties secretly agree to coordinate their actions, they can circumvent controls that would otherwise function as designed. For this reason, collusion is widely recognized as an inherent limitation of any control framework rather than a defect that better control design alone can fully eliminate.

Because collusion is deliberately concealed and involves cooperation among parties, it is generally difficult to detect through routine oversight and standard control testing. A control may be well designed and operating effectively as tested, yet still be defeated by coordinated action among the very people expected to provide independent checks on one another. This gap has significant implications for how boards, management, and assurance functions think about detection: reliance on preventive controls alone is typically insufficient, and detection often depends on other mechanisms such as investigation, whistleblowing channels, and data analytics.

The legal treatment and consequences of collusion vary considerably by jurisdiction, sector, and the nature of the underlying conduct, whether that involves fraud, anti-competitive arrangements, or other improper purposes. Organizations therefore generally treat collusion both as a compliance risk requiring appropriate policies and reporting channels, and as a limitation to be acknowledged when management represents on, and assurance functions opine on, the effectiveness of internal controls. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Boards and audit committees
Directors exercising oversight should understand that collusion is a recognized inherent limitation of internal control, meaning that even a well-designed control system cannot provide absolute assurance against coordinated, concealed misconduct. This informs how the board and its audit committee challenge management's representations about control effectiveness and consider the adequacy of whistleblowing and investigation mechanisms. The board's role here is generally one of oversight rather than direct operation of controls.
Management and control owners
Management typically owns the design and operation of internal controls, including segregation of duties and authorization controls that assume parties act independently. Control owners should recognize that these controls can be circumvented by colluding parties and consider complementary detective measures, such as data analytics and reporting channels, rather than relying on preventive controls alone.
Internal audit and assurance functions
Assurance providers testing control design and operating effectiveness should be aware that standard control testing may not surface collusion, because colluding parties can perform their assigned roles while jointly directing an improper outcome. Detection often depends on investigation, whistleblower information, or analytics, and assurance functions generally acknowledge this limitation when reporting on control effectiveness.
Compliance officers
Compliance functions typically address collusion through policies, training, reporting channels, and monitoring appropriate to the organization's risks. Because the legal treatment of collusion varies by jurisdiction, sector, and underlying conduct, compliance officers should tailor their approach to the applicable requirements rather than assuming a single universal standard applies.

Inside Collusion

Coordinated Circumvention of Controls
Collusion typically involves two or more individuals acting together to bypass or override controls that were designed to function on the assumption of independent action, such as segregation of duties.
Defeat of Segregation of Duties
A central feature is that responsibilities deliberately divided among different people to create checks and balances are undermined when those people cooperate improperly, allowing an activity to proceed without the intended independent scrutiny.
Internal, External, or Mixed Participants
Collusion may occur among employees within an organization, between employees and external parties such as vendors or customers, or across a combination of internal and external actors.
Concealment Element
Colluding parties generally coordinate not only to carry out an improper act but also to hide it, which makes detection through routine control testing more difficult.
Impact on Control Effectiveness
Collusion is generally recognized as an inherent limitation of internal control; even a well-designed control operating as intended can be defeated when parties conspire to circumvent it.
Relationship to Management Override
Collusion is distinct from, but can overlap with, management override of controls; both are commonly cited limitations that reduce the assurance any control system can provide.

Common questions

Answers to the questions practitioners most commonly ask about Collusion.

Does segregation of duties eliminate the risk of collusion?
No. Segregation of duties is designed to prevent a single individual from executing and concealing an improper act, but it does not eliminate collusion risk. When two or more people with complementary access or authority coordinate, they can defeat controls that assume the parties act independently. This is why control frameworks generally acknowledge collusion as an inherent limitation of internal control: a control's design may be sound and its operating effectiveness satisfactory, yet collusion can still override it. Management typically supplements segregation of duties with complementary or compensating controls, such as monitoring, mandatory rotation or leave, and independent oversight, to reduce the residual risk that collusion presents. Whether any given combination of controls is sufficient depends on the facts and on professional judgment.
Is collusion the same thing as fraud?
Not necessarily. Collusion describes a coordinated arrangement among two or more parties to act together, often to circumvent controls, evade detection, or misrepresent information. Fraud is a broader concept involving intentional deception for gain or to cause loss. Collusion can be a mechanism through which fraud is carried out, but the two are distinct: some fraud is committed by a single actor without any collusion, and some collusive arrangements (for example, certain anticompetitive coordination) may raise legal issues that are characterized differently from fraud. The precise legal characterization and consequences vary by jurisdiction, by the conduct involved, and by the applicable statutes and regulations, so the terms should not be used interchangeably. This entry is educational and not legal advice.
Which functions are responsible for addressing collusion risk, and how do their roles differ?
Responsibility is generally distributed across the lines of defense rather than owned by any single function. Management, as the first line, typically owns the design and operation of controls intended to deter and detect collusion within its processes. Risk and compliance functions, in the second line, generally set expectations, monitor, and advise on where collusion risk concentrates. Internal audit, as an independent assurance function, evaluates whether controls addressing collusion are designed appropriately and operating effectively, but does not own the controls themselves. The board and its relevant committees provide oversight of the overall approach and hold management accountable, without assuming operational responsibility. The exact allocation depends on the entity's structure, sector, and applicable governance arrangements.
What controls do organizations typically use to reduce residual collusion risk?
Because collusion can override segregation of duties, organizations commonly layer additional controls rather than relying on any single measure. These often include mandatory vacation or job rotation policies that interrupt sustained arrangements, independent review and reconciliation performed outside the colluding parties' control, data analytics and monitoring to surface anomalous patterns, whistleblowing and confidential reporting channels, and periodic reassessment of access rights and authority levels. The intent is to reduce residual risk to a level consistent with the organization's risk appetite, recognizing that collusion cannot be fully eliminated. The appropriate mix of controls is a matter of professional judgment and depends on the entity's processes, resources, and risk profile.
How can assurance functions test for indicators of collusion?
Assurance functions generally focus on both control design and operating effectiveness, and may extend testing to indicators that a control has been circumvented rather than simply confirming a control exists. Approaches can include analyzing transactions for patterns that suggest coordination, corroborating information from independent sources rather than relying on parties who could be acting together, reviewing exceptions and override activity, and evaluating whether compensating controls such as rotation and independent review are actually operating. Because collusion is intentionally concealed, testing may reduce but cannot guarantee detection, and findings typically warrant escalation and, where appropriate, specialist investigative or legal input. The scope and rigor of testing depend on the assessed risk and on the professional's judgment.
How should collusion risk be reflected in a risk assessment?
Collusion is generally treated as a factor that affects the gap between inherent and residual risk, because it can undermine controls that would otherwise reduce exposure. In practice, this means an assessment should consider not only the likelihood and impact of the underlying event but also the plausibility that multiple parties could coordinate to defeat the relevant controls, and how that affects confidence in residual risk estimates. Roles and access concentrations, the strength of compensating controls, and the presence of monitoring all inform this analysis. The way collusion risk is documented and rated depends on the organization's methodology, its risk appetite and tolerance, and the judgment of those performing the assessment; there is no single mandated approach across jurisdictions or frameworks.

Common misconceptions

A strong internal control system, if properly designed and operating effectively, eliminates the risk of collusion.
Control frameworks such as COSO generally acknowledge that collusion is an inherent limitation of internal control. Even effectively designed and operating controls can be circumvented when two or more parties cooperate, so no control system can provide absolute assurance against collusion.
Segregation of duties fully prevents fraud.
Segregation of duties is designed to reduce the risk of a single person acting improperly without detection. It relies on the assumption of independent action and can be defeated when the individuals whose duties are separated collude, which is why it is a mitigating control rather than a complete safeguard.
Collusion is only an internal problem among employees.
Collusion can involve internal employees, external parties such as vendors or customers, or combinations of both. Focusing detection efforts solely on internal actors can leave schemes involving third parties unaddressed.

Best practices

Recognize collusion as an inherent limitation of internal control when assessing residual risk, and avoid treating segregation of duties as a complete safeguard against improper activity.
Layer complementary controls, such as independent reconciliations, data analytics, rotation of duties, and mandatory vacations, so that defeating one control alone is less likely to conceal a scheme.
Extend monitoring beyond internal actors to relationships with vendors, customers, and other third parties where collusion with employees may occur.
Support detective controls with confidential reporting channels (such as whistleblower mechanisms), since collusive schemes designed to evade routine testing are often surfaced through reporting.
Clarify accountability across the lines of defense: management owns the design and operation of anti-collusion controls, while assurance functions such as internal audit independently evaluate whether those controls address collusion risk, and the board or audit committee oversees the overall approach.
Document the residual risk of collusion in risk assessments and escalate significant exposures to the appropriate committee, treating these entries as educational rather than a substitute for legal, audit, or compliance advice tailored to the entity's facts and jurisdiction.