Skip to main content
Category: Fraud Risk Management

Fraud Scheme

Also known as: Scheme to Defraud, Scheme and Artifice to Defraud
Simply put

A fraud scheme is a deceptive practice designed to gain an unlawful financial advantage by relying on deception. Common examples include identity theft, phishing, and Ponzi schemes, which pay earlier investors using funds contributed by more recent investors. Fraud generally becomes a crime when it involves a knowing misrepresentation of the truth intended to induce another to part with something of value.

Formal definition

A fraud scheme is an organized method or plan that uses deception to obtain money, property, or another unlawful gain. In the U.S. federal context, the underlying concept of a 'scheme and artifice to defraud' has been construed broadly and may encompass related conduct such as embezzlement, described as the fraudulent appropriation to one's own use of money or goods entrusted to one's care. Fraud as such relies on deception to achieve a gain and becomes a crime when it involves a knowing misrepresentation of the truth. Schemes range across internal and external threat types, for example, identity theft, phishing, and Ponzi arrangements, and organizations typically address them through detection, deterrence, and control activities. The precise legal elements, applicable statutes, and available remedies vary by jurisdiction, and this entry is educational rather than legal or compliance advice.

Why it matters

Fraud schemes represent one of the most direct threats to an organization's assets, financial integrity, and reputation, and they span both internal actors (such as employees who embezzle funds entrusted to their care) and external actors (such as those perpetrating identity theft or phishing). Because fraud relies on deception to achieve a gain, it can evade routine transactional review and often surfaces only when controls are specifically designed to detect it. For boards and management, understanding the range of scheme types is a prerequisite to allocating detection and deterrence resources appropriately.

The distinction between fraud as a general concept and fraud as a crime matters for how organizations respond. Fraud generally becomes a criminal matter when it involves a knowing misrepresentation of the truth intended to induce another to part with something of value. In the U.S. federal context, the underlying notion of a 'scheme and artifice to defraud' has been construed broadly and may encompass related conduct such as embezzlement. However, the precise legal elements, applicable statutes, and available remedies vary by jurisdiction, and characterizing conduct as a chargeable offense is a legal determination rather than a compliance conclusion.

Because schemes evolve and take many forms, from Ponzi arrangements that pay earlier investors with funds from more recent ones, to phishing and identity theft, organizations that fail to recognize this variety may leave gaps in their control environment. Recognizing the wide range of internal and external fraud threats is generally regarded as essential to detecting and deterring them, and it informs where an organization concentrates its anti-fraud efforts.

Who it's relevant to

Chief Compliance Officers
Compliance functions typically own the design and monitoring of anti-fraud policies and awareness efforts. Understanding the variety of internal and external scheme types helps compliance leaders target training, detection mechanisms, and deterrence measures where the organization is most exposed.
Chief Risk Officers and Risk Functions
Fraud is a risk category that generally feeds into enterprise risk assessment. Risk leaders consider how fraud schemes affect the organization's risk profile and how controls reduce residual exposure, coordinating with compliance and assurance functions rather than duplicating their operational roles.
Internal Auditors and Assurance Functions
Assurance functions test whether anti-fraud controls are both well designed and operating effectively, and they may investigate suspected schemes such as embezzlement. Recognizing the wide range of internal and external threats supports the scoping of fraud-focused audit work.
General Counsel and Legal Teams
Whether conduct rises to a chargeable fraud offense, involving a knowing misrepresentation of the truth, is a legal determination. Legal teams assess applicable statutes, elements, and remedies, which vary by jurisdiction, and advise on investigations, reporting obligations, and litigation exposure.
Boards and Audit Committees
The board and its committees hold oversight responsibility for the adequacy of the organization's anti-fraud environment. They generally look to management and assurance functions for reporting on fraud risk, detection efforts, and the response to any identified schemes, without assuming operational duties themselves.

Inside Fraud Scheme

Fraudulent Act
The intentional deception at the core of a scheme, typically involving misrepresentation, concealment, or abuse of position for personal or organizational gain. Distinguished from error, which lacks intent.
Perpetrator and Motivation
The individual or group carrying out the scheme, often understood through pressures, opportunities, and rationalizations. Perpetrators may be internal (employees, management) or external (vendors, customers), and collusion can defeat controls designed on a single-person basis.
Concealment Method
The techniques used to hide the fraud, such as falsified records, overriding of controls, or circumvention of segregation of duties. Concealment is often what distinguishes a sustained scheme from an isolated incident.
Financial or Non-Financial Impact
The consequences to the organization, which may include direct asset loss, misstated financial reporting, reputational harm, or regulatory exposure. Impact and likelihood are assessed separately when evaluating fraud risk.
Control Environment Weakness
Gaps in control design or operating effectiveness that the scheme exploits, such as inadequate authorization, weak reconciliation, or management override capability. Identifying the exploited weakness is central to remediation.
Detection and Response Pathway
The mechanisms through which a scheme is identified (tips, monitoring, audit, reconciliation) and the organizational response. These typically span management, compliance monitoring, and independent assurance functions with different accountabilities.

Common questions

Answers to the questions practitioners most commonly ask about Fraud Scheme.

Is fraud risk the responsibility of the compliance function alone?
No. While a compliance function often supports anti-fraud efforts through policy, training, and monitoring, fraud risk is typically addressed across the three lines. Management (first line) owns the design and operation of preventive and detective controls within business processes; risk and compliance functions (second line) typically set frameworks, provide oversight, and challenge; and internal audit (third line) generally provides independent assurance over the effectiveness of those controls. The board or its audit committee usually retains oversight responsibility. Treating fraud as a single-function concern tends to leave gaps, because accountability for prevention sits primarily with process owners in management. Where responsibility falls depends on the entity's structure and the applicable governance model.
Does the presence of anti-fraud controls mean a fraud scheme cannot occur?
No. Controls are generally designed to reduce risk, not eliminate it. Even well-designed controls address inherent risk down to some level of residual risk, and residual risk is rarely zero. Fraud schemes frequently involve concealment, collusion, or management override, any of which can defeat controls that are otherwise sound in design. A control that is well designed may still fail in operating effectiveness, and the distinction between design and operating effectiveness matters when assessing exposure. Anti-fraud programs are therefore generally understood as risk-mitigation measures rather than guarantees.
How can an organization begin identifying the fraud schemes most relevant to it?
Many organizations start with a structured fraud risk assessment that inventories potential schemes by process, actor, and asset exposed. This typically considers how a scheme might be perpetrated, who could execute it, and what conditions or incentives could contribute. Assessments often distinguish inherent risk from residual risk after existing controls are considered, and rate exposure by likelihood and impact separately rather than as a single score. The output generally informs where preventive and detective controls, monitoring, and assurance activities should be prioritized. The specific schemes that warrant attention depend on the entity's operations, industry, and prior incidents.
What is the difference between preventive and detective controls in addressing a fraud scheme?
Preventive controls are generally intended to stop a scheme from occurring, for example through segregation of duties, authorization limits, or access restrictions. Detective controls are typically designed to identify a scheme after it has begun or occurred, for example through reconciliations, exception reporting, data analytics, or whistleblower channels. Most anti-fraud programs use both, because preventive controls can be circumvented and detective controls can shorten the time a scheme remains undetected. The appropriate mix depends on the specific scheme, the cost of controls, and the entity's risk appetite and tolerance.
How should management override of controls be considered when analyzing fraud schemes?
Management override is often treated as a distinct concern because those with authority to approve transactions or adjust records may be able to circumvent controls that constrain other employees. Analysis of fraud schemes generally accounts for this by considering who holds override capability and what compensating measures exist, such as independent review, board or audit committee oversight, monitoring of manual journal entries, and protected reporting channels. Because override can defeat otherwise effective controls, it is frequently a focus for internal audit and for the board's oversight of the control environment. How it is addressed depends on the entity's governance structure and applicable frameworks.
What role does the board or audit committee play regarding fraud schemes?
The board, often acting through an audit committee, typically holds an oversight role rather than an operational one. This generally includes overseeing management's fraud risk management approach, the tone at the top, the adequacy of whistleblower arrangements, and the independence and scope of internal audit. Under some governance codes and frameworks, the board is expected to satisfy itself that management has established appropriate systems, but designing and operating those systems generally remains a management responsibility. The precise duties depend on the applicable law, listing rules, and governance code, which vary by jurisdiction and entity type.

Common misconceptions

Preventing fraud is solely the responsibility of internal audit or the assurance function.
Ownership of fraud risk generally sits with management as part of first-line controls, while compliance may monitor and internal audit provides independent assurance over control effectiveness. The board and its committees typically exercise oversight. Treating fraud as one function's job blurs these distinct accountabilities.
A strong control framework eliminates fraud risk.
Controls generally reduce risk from an inherent to a residual level rather than eliminating it. Management override, collusion, and evolving schemes mean residual fraud risk typically remains, which is why detection mechanisms complement preventive controls.
All fraud schemes involve theft of assets and produce immediate financial loss.
Schemes can also involve financial statement misrepresentation, corruption, or non-financial harm such as reputational or regulatory consequences, and impact may be delayed or indirect. Categorizing a scheme by asset loss alone can understate its significance.

Best practices

Assign clear ownership for fraud risk to management as a first-line responsibility, while defining separate monitoring roles for compliance and independent assurance roles for internal audit, so accountability is not conflated across functions.
Assess fraud risk by evaluating inherent risk, the effectiveness of existing controls, and the resulting residual risk, rather than assuming controls eliminate exposure.
Design controls to address the possibility of collusion and management override, recognizing that segregation-of-duties controls built for a single actor may not hold where parties cooperate.
Combine preventive controls with detection mechanisms such as whistleblower channels, monitoring, and reconciliations, since prevention alone typically leaves residual risk.
Evaluate both control design and operating effectiveness when reviewing fraud-related controls, as a well-designed control that does not operate as intended provides limited protection.
Escalate significant fraud risks and incidents to the board or relevant committee for oversight, keeping oversight distinct from the operational response managed by the first line.