Skip to main content
Category: Fraud Risk Management

Report to the Nations

Also known as: ACFE Report to the Nations, Occupational Fraud: A Report to the Nations
Simply put

The Report to the Nations is a recurring global study of occupational fraud published by the Association of Certified Fraud Examiners (ACFE). It analyzes real fraud cases investigated by Certified Fraud Examiners to describe how occupational fraud is committed, detected, and addressed. The report is a widely referenced source of fraud-related data, but it is a research publication rather than a law, regulation, or mandatory standard.

Formal definition

The Report to the Nations is the ACFE's periodic research study on occupational fraud, produced since 1996, drawing on real fraud cases submitted by Certified Fraud Examiners (CFEs). The 14th edition analyzes 2,402 cases of occupational fraud from 143 countries and territories, and reporting summaries indicate it addresses common fraud schemes, behavioral red-flag indicators, and response strategies. It functions as descriptive, non-binding benchmarking and reference material that governance, risk, and compliance professionals may use to inform fraud risk assessment and anti-fraud program design; it does not constitute a regulatory requirement, framework, or professional standard, and its findings reflect the characteristics of the cases studied rather than the full population of occupational fraud.

Why it matters

Occupational fraud, in which individuals misuse their position within an organization for personal gain, is a persistent risk that governance, risk, and compliance professionals are expected to understand and mitigate. The Report to the Nations is one of the most widely referenced sources of descriptive data on how such fraud is committed, detected, and addressed, and it has been produced by the ACFE since 1996. For boards, audit committees, and anti-fraud program owners, it offers a shared vocabulary and a body of case-based observations that can inform how an organization frames its own fraud risk.

Because the report draws on real cases investigated by Certified Fraud Examiners, it can help management and assurance functions benchmark their anti-fraud practices against patterns observed across a large sample of cases. Reporting summaries indicate the 14th edition addresses common fraud schemes, behavioral red-flag indicators, and response strategies, all of which are relevant inputs to a structured fraud risk assessment and to the design of preventive and detective controls.

It is important to recognize the report's limits. It is a research publication, not a law, regulation, framework, or professional standard, and it imposes no obligations on any organization. Its findings reflect the characteristics of the cases studied rather than the full population of occupational fraud, so its data should be treated as directional benchmarking material rather than a definitive measure of fraud in any given sector or jurisdiction. Professionals should apply their own judgment and consult applicable legal and regulatory requirements when translating the report's observations into program decisions.

Who it's relevant to

Chief Compliance and Fraud Risk Officers
Those who own or contribute to anti-fraud programs may draw on the report's descriptions of common schemes, behavioral indicators, and response strategies to inform fraud risk assessments and program design. It serves as benchmarking input rather than a required standard, and its findings should be weighed against the organization's own facts and applicable requirements.
Internal Auditors and Assurance Functions
Internal audit and other assurance functions may reference the report's case-based observations when planning fraud-related audits or evaluating the design and operating effectiveness of anti-fraud controls. The report is descriptive research and does not substitute for an audit standard or an entity-specific control assessment.
Boards and Audit Committees
Board members and audit committees exercising oversight of fraud risk may use the report to inform their understanding of how occupational fraud is committed and detected. It supports oversight discussions but does not create an oversight duty or establish a regulatory expectation; accountability for the design and operation of controls remains with management.
General Counsel and Legal Advisors
Legal advisors may find the report useful as background context on occupational fraud patterns when advising on program design or investigations. Because it is educational research and not legal authority, it should not be treated as a source of legal requirements, which vary by jurisdiction, sector, and entity type.

Inside Report to the Nations

Occupational Fraud Focus
The report centers on occupational fraud, generally defined as the use of one's occupation for personal enrichment through the deliberate misuse or misapplication of an employing organization's resources or assets. Its scope is typically limited to this category rather than all forms of financial crime or misconduct.
Fraud Scheme Categories
The publication commonly organizes occupational fraud into broad categories such as asset misappropriation, corruption, and financial statement fraud. These categories are analytical groupings used to describe how schemes are perpetrated, and the specific definitions and boundaries depend on the report's own methodology.
Case-Based Data
Findings are typically drawn from cases submitted by fraud examination professionals rather than from a comprehensive census of all fraud. As a result, the data reflects detected and reported cases and is subject to the limitations of any self-reported, non-random sample.
Detection Methods and Controls
The report generally examines how frauds are initially detected (for example, through tips, internal audit, or management review) and discusses anti-fraud controls. This information can inform control design considerations but does not by itself establish the operating effectiveness of any control in a given organization.
Perpetrator and Victim Characteristics
Entries commonly summarize observed attributes associated with reported cases, such as perpetrator role or the type and size of victim organizations. These are descriptive observations from the sample and should not be treated as predictive rules for any individual entity.

Common questions

Answers to the questions practitioners most commonly ask about Report to the Nations.

Is the Report to the Nations an official regulatory report that entities are required to file or comply with?
No. It is a research publication, not a legal or regulatory instrument. It does not impose obligations, and nothing in it constitutes a filing requirement, a binding standard, or a rule that entities must comply with. Any anti-fraud obligations an entity faces derive from applicable statutes, regulations, listing rules, or contractual commitments in its jurisdiction and sector, not from this report. The report is educational reference material and should not be treated as legal, audit, or compliance advice.
Do the report's findings represent the true rate or total cost of occupational fraud across all organizations?
Not precisely. The figures are drawn from a sample of cases submitted by practitioners, not from a comprehensive census of all organizations, and they generally reflect only detected and reported fraud. Undetected schemes are, by definition, not captured, so headline statistics should be read as informative estimates about the cases studied rather than definitive measures of prevalence or total losses. Findings can also vary by region, sector, and entity type, and methodology may differ across editions.
How can a compliance function use the report's findings without overstating their authority?
The findings can be used as illustrative context to support awareness, training, and risk discussions, provided they are cited as research observations rather than mandates. Generally, a compliance function would reference themes such as common scheme types or detection methods to prompt discussion, while grounding any actual controls or policies in the entity's own risk assessment and in applicable legal requirements. It is prudent to note the report's sample-based limitations whenever findings are presented to a board, committee, or management audience.
Which function typically owns follow-up on themes raised by the report, and where does accountability sit?
Ownership depends on the activity. Designing and operating anti-fraud controls is generally a management responsibility within the first line, while compliance monitoring and internal audit assurance sit in the second and third lines respectively. The board or its audit committee typically holds oversight responsibility for the anti-fraud program as a whole but does not perform the operational work. When using report themes, an organization should map any resulting action to the function that actually owns it rather than treating the report as assigning duties.
How might the report inform an entity's fraud risk assessment?
It can serve as one external input among several, helping teams consider whether commonly observed scheme categories or detection channels are relevant to their own environment. However, it does not substitute for an entity-specific assessment, which should weigh the organization's own inherent risks, existing controls, and resulting residual risk in light of its facts and circumstances. Generalized statistics should inform, not replace, professional judgment about likelihood and impact for the specific organization.
Can the report's data be used to benchmark our organization's fraud losses against peers?
With caution. Because the data reflects a sample of submitted and detected cases rather than a full population, direct benchmarking can be misleading and may not reflect differences in detection maturity, reporting practices, sector, or jurisdiction. Any comparison should be framed as directional context rather than a precise peer benchmark, and users should acknowledge the methodological limitations when presenting such comparisons to decision-makers.

Common misconceptions

The Report to the Nations is a binding standard or regulatory requirement that organizations must follow.
It is a research publication offering educational insight into occupational fraud trends. It is not law, a listing rule, or a mandatory framework, and it does not impose compliance obligations. Requirements affecting an organization arise from applicable statutes, regulations, and its own policies, which vary by jurisdiction, sector, and entity type.
The report's statistics represent the true, complete prevalence and cost of fraud across all organizations.
The findings are generally based on cases submitted by practitioners, which reflect detected and reported fraud rather than a random or exhaustive sample. Undetected and unreported fraud is not captured, so figures should be read as illustrative of observed patterns, not as precise measures applicable to any specific organization.
Implementing the controls associated with lower losses in the report guarantees fraud prevention or satisfies an organization's oversight duties.
The report can inform control design, but effective anti-fraud programs also depend on operating effectiveness, an organization's own risk assessment, and coordinated roles across management, assurance functions, and the board. No control set eliminates fraud risk, and adopting reported practices does not by itself discharge governance or compliance responsibilities.

Best practices

Treat the report as an educational benchmark for awareness and discussion, not as a compliance standard, and validate any conclusions against your organization's own facts, jurisdiction, and risk profile.
Use the report's detection findings to evaluate whether your organization has accessible reporting channels, such as tip mechanisms, while separately testing the operating effectiveness of those channels rather than assuming design alone is sufficient.
Map the fraud scheme categories described in the report to your own risk assessment so that management can identify inherent risks and evaluate the residual risk remaining after existing controls.
Clarify accountability when acting on the report's insights: assign anti-fraud control operation to management, independent testing to internal audit or other assurance functions, and oversight to the board or its relevant committee.
Interpret reported statistics with appropriate caution, recognizing the sample's limitations, and avoid extrapolating aggregate figures to predict outcomes for any individual person or business unit.
Consult qualified legal, audit, and compliance professionals before relying on the report to shape investigations, disciplinary action, or program design, since these matters depend on facts, jurisdiction, and professional judgment.