How to help clients prevent employee theft: a guide for accountants
Practical internal controls to help your clients reduce the risk of employee theft.

Written by Lena Hanna—Trusted CPA Guidance on Accounting and Tax. Read Lena's full bio
Published Thursday 9 July 2026
Table of contents
Key takeaways
- Employee theft costs organisations a median of $145,000 per case, and small businesses with fewer than 100 employees are disproportionately affected due to limited internal controls.
- Segregation of duties, regular reconciliation, and clear authorisation limits are the most effective controls you can help clients put in place to reduce the risk of occupational fraud.
- Cloud accounting tools give you and your clients real-time visibility into transactions, automated audit trails, and granular user permissions that make it harder for fraud to go undetected.
- When theft is discovered, your role is to guide the client through documenting evidence, securing accounts, and seeking appropriate legal advice before taking further action.
The scale of employee theft
Employee theft remains one of the most persistent financial risks your clients face, and it's one where your advisory role can make a real difference. Understanding the scope of the problem helps you frame the conversation with clients who may underestimate their exposure.
According to the Association of Certified Fraud Examiners (ACFE) 2024 Report to the Nations, the median loss per occupational fraud case was $145,000. Occupational fraud typically lasts 12 months before detection, giving perpetrators significant time to cause damage. Notably, 43% of fraud cases were detected through tips, highlighting the value of reporting mechanisms over relying solely on audits.
You'll recognise the fraud triangle: opportunity, pressure, and rationalisation. When all 3 elements converge, the risk of employee theft increases significantly. Small organisations with fewer than 100 employees are disproportionately affected because they often lack the internal controls and oversight that larger businesses have in place.
For your practice, this means proactively raising fraud prevention with clients rather than waiting for a problem to surface. Building this into your advisory conversations positions you as a trusted partner who helps protect their business.
Common types of employee theft
Employee theft takes many forms, and recognising the most common types helps you identify vulnerabilities in your clients' operations. Here are the categories to watch for.
- Cash theft (skimming and larceny). Skimming involves taking cash before it's recorded in the accounting system, while larceny occurs after recording. Both are more common in businesses that handle cash transactions regularly.
- Inventory theft. Employees may steal physical stock, raw materials, or supplies. This is particularly common in retail, hospitality, and manufacturing businesses where inventory controls are weak.
- Expense reimbursement fraud. Employees submit inflated, fictitious, or personal expenses for reimbursement. This can range from padding travel claims to submitting receipts for purchases never made.
- Payroll fraud. This includes ghost employees on the payroll, falsified timesheets, and unauthorised pay increases. It's often carried out by employees with access to payroll systems.
- Data and intellectual property theft. Employees may steal customer lists, proprietary processes, financial data, or trade secrets. This type of theft can be harder to detect but equally damaging to the business.
Warning signs to watch for in client accounts
As the professional reviewing your clients' financial records, you're well placed to spot early warning signs of employee theft. Train your team to flag these patterns during routine reviews and reconciliations.
- Reconciliation discrepancies. Unexplained differences between bank statements, ledger entries, and supporting documents can signal that transactions have been manipulated or concealed.
- Unusual transaction patterns. Watch for transactions just below approval thresholds, frequent round-number payments, or an increase in voids and refunds that don't follow normal business patterns.
- Lifestyle changes in employees handling finances. Sudden changes in spending habits or lifestyle that don't match an employee's salary may warrant closer scrutiny of accounts they manage.
- Resistance to audits or process changes. Employees who push back against new controls, resist handovers during leave, or become defensive about their processes may be protecting fraudulent activity.
- Sudden interest in working alone or handling specific accounts. An employee who insists on managing particular accounts without oversight, or who consistently works outside normal hours, could be creating opportunities for theft.
Internal controls to help prevent employee theft
Internal controls are the most practical tool you can recommend to clients for reducing their exposure to employee theft. Here are 10 controls to build into both your advisory recommendations and your practice workflow.
1. Segregation of duties
Advise clients to split financial responsibilities so that no single employee controls an entire process from start to finish. For example, the person who approves payments shouldn't also be the one reconciling bank statements.
In smaller businesses where headcount is limited, you can help by taking on one side of the segregation yourself. Handling the reconciliation or review function as part of your engagement gives the client an independent layer of oversight they can't create internally.
Within your practice, document which segregation arrangements are in place for each client. This makes it easier to identify gaps and ensures your team knows what to check during regular reviews.
2. Clear authorisation limits
Help clients set defined approval thresholds for transactions, purchases, and expense claims. Every payment above a set amount should require sign-off from a second person, and these limits should be documented in the company's financial policies.
Review these limits with clients annually. As their business grows, thresholds that worked when revenue was lower may need adjusting. Build this review into your annual planning or advisory meetings.
3. Regular bank reconciliation and statement review
Encourage clients to reconcile bank accounts at least monthly, and ideally more frequently. Regular reconciliation catches discrepancies early, before small thefts accumulate into significant losses.
Where you handle reconciliation as part of your service, flag any unusual items promptly rather than batching queries at period end. If the client handles it internally, offer training on what to look for and set up a schedule they can follow.
Recommend that someone other than the person processing payments reviews the bank statements directly. This simple step adds an independent check that's difficult to circumvent.
4. Inventory management and auditing
For clients with physical stock, recommend regular inventory counts and spot checks. Comparing physical counts to system records reveals shrinkage that could indicate theft.
Help clients set up inventory tracking processes and schedule periodic audits. Even a quarterly spot check of high-value items sends a clear message that inventory is being monitored, which acts as a deterrent.
5. Petty cash controls
Petty cash is one of the easiest targets for employee theft. Advise clients to set a maximum petty cash float, require receipts for every withdrawal, and have someone independent reconcile the fund regularly.
Where possible, recommend reducing reliance on petty cash altogether. Digital payment methods create automatic records and are easier to track, making them a simple upgrade for many businesses.
6. Background checks during hiring
Recommend that clients conduct background checks on employees who'll handle finances, inventory, or sensitive data. Reference checks, qualification verification, and credit history reviews can highlight potential risks before they materialise.
While you won't typically conduct these checks yourself, you can advise clients on which roles warrant screening and what to look for. Include this as part of your onboarding advisory for new clients.
7. Clear policies and communication
Help clients develop a written policy on fraud prevention, covering expected behaviour, reporting channels, and consequences for theft. A clear policy removes ambiguity and sets expectations from the start.
Offer to review or help draft these policies as part of your advisory service. Ensure the policy is communicated during onboarding and reinforced periodically so that all employees understand the standards.
8. Active management participation
Encourage business owners to stay involved in financial oversight. When management regularly reviews reports, signs cheques, and asks questions about transactions, it signals that the business is paying attention.
Part of your role is to make this easy. Provide clients with clear, concise reporting that highlights the numbers they should be watching. The simpler you make oversight, the more likely they are to stay engaged.
9. Monitoring and surveillance
For clients with physical premises, recommend security measures such as CCTV in areas where cash or inventory is handled. Digital monitoring, including transaction logs and system access reports, complements physical surveillance.
Cloud accounting platforms make digital monitoring more accessible by providing real-time audit trails and activity logs. Advise clients to review these logs periodically, and build log reviews into your own engagement workflow.
10. Anonymous reporting mechanisms
Given that the ACFE found 43% of fraud cases are detected through tips, help clients set up a confidential reporting channel. This could be as simple as a dedicated email address or a third-party whistleblowing service.
Make sure employees know the channel exists and that reports are taken seriously. Encourage clients to communicate their anti-fraud policies regularly. Within your practice, note which clients have reporting mechanisms in place and follow up with those who don't.
How cloud accounting technology strengthens oversight
Cloud accounting technology gives you and your clients the tools to maintain stronger oversight without adding manual effort. The right platform turns fraud prevention from a periodic exercise into continuous monitoring.
Real-time visibility into transactions means you can spot anomalies as they happen, rather than discovering them weeks or months later during reconciliation. Xero's cloud accounting software provides automated bank feeds that pull transactions directly from the bank, reducing the risk of manual data manipulation.
Audit trails record every change made in the system, including who made it and when. This creates accountability and makes it significantly harder for someone to alter records without detection. You can review these trails as part of your regular client reviews.
Granular user permissions let you help clients control exactly who can access, edit, or approve different types of transactions. Restricting access based on role supports segregation of duties and reduces the window for unauthorised activity.
For your practice, cloud accounting also streamlines the review process. Instead of waiting for clients to send files or provide access to on-premise systems, you can monitor client accounts remotely and in real time, making your advisory work more proactive and efficient.
What to do when theft is discovered
Discovering employee theft puts your client in a difficult position, and your guidance through the process is critical. Acting calmly and methodically protects both the evidence and the business.
The first step is to document everything. Advise the client to preserve all relevant financial records, transaction logs, emails, and any other evidence before confronting the employee. Taking screenshots, securing backups, and noting dates and amounts creates a clear record that can support further action.
Next, secure the accounts. Change passwords, revoke the employee's access to financial systems, and update authorisation protocols. This prevents further losses while the situation is being investigated.
Advise the client to seek legal counsel before taking disciplinary action. Under Malaysia's Employment Act 1955, employers must follow due process when addressing employee misconduct, including conducting a domestic inquiry. Getting legal advice early helps the client avoid procedural missteps that could complicate recovery or enforcement.
Your role as the accountant is to quantify the loss, prepare a clear financial summary of the impact, and support the client through any investigation or insurance claims. Document your findings in a format that's useful for both legal proceedings and internal decision-making.
Strengthen your clients' defences with Xero
Helping clients prevent employee theft is a high-value advisory service that builds trust and long-term relationships. Cloud accounting tools give you the real-time visibility, automated audit trails, and access controls to make fraud prevention part of your standard practice workflow.
FAQs on preventing employee theft
Here are some frequently asked questions about preventing employee theft.
What internal controls can employers use to prevent theft?
The most effective controls include segregation of duties, clear authorisation limits, regular bank reconciliation, and anonymous reporting channels. Combining multiple controls creates layers of protection that are harder to circumvent than any single measure.
How can accountants help clients detect employee fraud?
You can review financial records for reconciliation discrepancies, unusual transaction patterns, and anomalies in expense claims or payroll. Regular independent reviews, combined with cloud-based audit trails, give you visibility into client accounts that internal staff may not provide objectively.
Is employee theft common in small businesses?
Yes. According to the ACFE 2024 Report to the Nations, small organisations with fewer than 100 employees are disproportionately affected by occupational fraud. Limited internal controls and fewer layers of oversight create more opportunities for theft to occur and go undetected.
What should a business do if they discover employee theft?
The business should document all evidence, secure financial accounts, and seek legal advice before confronting the employee. In Malaysia, the Employment Act 1955 requires employers to follow due process for misconduct, so professional guidance is essential to protect the business's position.
How does cloud accounting help prevent employee theft?
Cloud accounting provides real-time transaction visibility, automated bank feeds, detailed audit trails, and granular user permissions. These features support segregation of duties, reduce opportunities for manual manipulation, and make it easier for you and your clients to spot irregularities before they escalate.
Disclaimer
Xero does not provide accounting, tax, business or legal advice. This guide has been provided for information purposes only. You should consult your own professional advisors for advice directly relating to your business or before taking action in relation to any of the content provided.
Become a Xero partner
Join the Xero community of accountants and bookkeepers. Collaborate with your peers, support your clients and boost your practice.