Corporate fraud remains one of the most persistent threats facing organizations worldwide – not just because of its financial impact, but because it often originates from those who were once trusted the most.
The latest KPMG report, Global Profiles of the Fraudster, sheds light on the recurring traits, techniques, and circumstances that enable fraud to flourish. As internal auditors, governance leaders, and executives, understanding these patterns is the first step in tightening our defenses.
The Profile of a Typical Fraudster
One of the most unsettling insights from the report is how “normal” the typical fraudster appears.
- Most are male, aged 36–55
- They often have long tenures (6+ years)
- They are frequently well-respected within the organization
In other words, fraud doesn’t usually come from outsiders. It emerges from those within, from people we think we know.
The Most Common Types of Fraud
While fraud can take many forms, the report highlights some recurring patterns:
- Asset misappropriation (e.g., embezzlement)
- Procurement fraud
- Financial manipulation
These are not just technical breaches, they’re breaches of trust that erode integrity across departments.
Where Fraud Happens, And Why
Fraud is not limited to a single department. However, certain areas consistently show greater vulnerability:
- Operations
- Finance
- Procurement
- Executive offices (including the CEO’s office)
The underlying enabler? Weak internal controls. When oversight is inconsistent or absent, the opportunity to commit fraud increases, especially in high-trust or siloed environments.
How It’s Usually Detected
Interestingly, most frauds aren’t caught by structured audits or automated systems.
They’re exposed through whistleblower tips or informal channels.
This underscores the importance of creating a culture where speaking up is safe and where employees know their concerns will be heard and acted on.
Fraud is Often a Team Sport
Over 50% of cases involve multiple perpetrators. These are not always elaborate conspiracies – often, they’re small groups exploiting loopholes, enabled by familiarity and mutual cover.
The idea of the “lone fraudster” is increasingly outdated.
What Organizations Can Do
This report reinforces several key imperatives for fraud prevention:
- Build and maintain strong internal controls
- Promote a culture of transparency and ethics
- Encourage and protect whistleblower mechanisms
- Recognize that tenure and respectability are not substitutes for oversight
From Awareness to Action
The biggest threat isn’t that fraud exists, it’s that we underestimate who might commit it, and how easily it can happen under our noses.
By staying vigilant, designing smarter controls, and fostering open cultures, organizations can mitigate risk – not by suspicion, but by structure.
So what’s your take on the report’s findings?
What do you believe deserves more emphasis or might still be missing from the conversation?