The conversation almost always opens the same way. A business owner calls, and within two minutes comes a version of the same sentence: she had been with the company eleven years, and there was never any reason to question it. That sentence is the finding. Not the trust itself, which is usually well-placed, but the fact that trust had been asked to do a control’s job.
Occupational fraud in small businesses is rarely sophisticated. It is almost never committed by an outsider. Most of the time a structural gap made it possible, and a few hours of attention could have closed it. Small business fraud prevention is less about vigilance than about structure. September is the right month to do that work. There is still a full quarter before year-end close, before 1099 season, and before the audits some organizations face. Fixing a control weakness now is planning. Fixing it in February is damage control.
This blog is a practical review of the internal controls for small business that matter most. It covers segregation of duties on a small team, what to check in the accounting system, and what to activate at the bank. It also covers payroll oversight and one 2026 reporting change that quietly removed a layer of vendor verification.
The Association of Certified Fraud Examiners publishes the definitive global study on occupational fraud every two years, and the newest edition was released in 2026. Occupational Fraud 2026: A Report to the Nations examined 2,402 cases across 143 countries, representing more than $3.4 billion in losses.
Several findings deserve a small business owner’s attention:
The most consequential finding is this one. Organizations with fewer than 100 employees recorded a median loss of $126,000 — higher than the $123,000 median at organizations with more than 10,000 employees.
The smaller organization absorbed the larger loss.
That outcome is arithmetic, not character. A $126,000 loss at a 25-person company can be an existential event; at a large enterprise it is a rounding error. Small organizations also have fewer barriers between an opportunity and a decision. The same report found that while 85% of large organizations maintain an established reporting mechanism, only about 25% of small businesses do.
Weak controls rarely appear on their own. They usually sit alongside other financial warning signs, and our guide on the 8 Financial Red Flags Small Business Owners Should Never Ignore walks through the full set.
The textbook principle is to separate the person who authorizes a transaction, the person who records it, and the person who holds the asset. In a 400-person company that is an org chart exercise. In a six-person company, owners routinely describe it as impossible.
It is not impossible. It means the third party has to be the owner. A second bookkeeper is not required. Removing a single link from the chain is.
None of this requires additional headcount. It requires the owner to occupy one seat in the process rather than delegating it entirely.
Nearly every business DWG CPA onboards presents the same finding. One person holds administrator rights in the accounting system, is an authorized user on the bank account, carries the corporate card, and receives the bank statements.
That person is usually very good at the job. The issue is that the structure has no mechanism for telling anyone if that ever stops being true.
If a bookkeeper can void a check and rebuild the register, the reconciliation proves very little.
This is the least visible item on the list and likely the highest return on time invested. A single call to a business banker covers all of it.
Most of these are free. They go unused because no one set aside the time to turn them on.
Where payroll is outsourced, the liability picture is worth understanding precisely. The IRS position is unambiguous: the employer remains the responsible party for the deposit and payment of federal tax liabilities, even when funds have already been forwarded to the provider. If the provider fails to deposit, penalties and interest are assessed against the employer, and an owner can be held personally liable for certain unpaid federal taxes.
The IRS recommends two steps that carry no cost:
One development this year has received almost no attention from a controls standpoint. Among the many provisions in what the One Big Beautiful Bill Act actually means for small business owners, one change quietly altered how much a business knows about the people it pays.
The reporting threshold for Forms 1099-NEC and 1099-MISC rose from $600 to $2,000 for payments made in 2026, with inflation indexing beginning in 2027. For most businesses that means meaningfully fewer forms to prepare.
But consider what the old threshold was quietly accomplishing. Every vendor paid more than $600 generated a form, which required a W-9, which required a legitimate taxpayer identification number attached to a real entity. That compliance obligation also functioned as a light annual verification of the vendor list.
This is not an argument against the new threshold. It is an argument for replacing the verification it used to supply. A W-9 should still be collected from every vendor before the first payment, regardless of the amount anticipated. Vendor setup should remain owner-approved, and the vendor list deserves an annual review that compares addresses against employee addresses and flags entities with no web presence, no phone number, or a P.O. box paired with a generic name. y. It is the result of decisions and actions taken in the months before December 31, not in the weeks after.
Reconcile monthly through November: A year-end that follows 11 months of clean reconciliations is orderly. A year-end that follows 6 months of deferred reconciliations is a crisis. The goal is to arrive at December with only one month left to close, not three or four.
Resolve outstanding receivables: Aging receivables that aren’t going to be collected need to be identified and potentially written off before year-end. Bad debt write-offs require documentation — a record of the debt, evidence of collection attempts, and a business decision that the amount is uncollectable.
Conduct an inventory count if applicable: For product-based businesses, a year-end physical inventory count is often required for accurate financial reporting and tax purposes. This takes time to organize and should be planned in advance.
Document everything: Deductions require documentation. Vehicle mileage logs, receipts for meals and entertainment, home office calculations, contractor payments for 1099 purposes, all of these need to be current and organized before the filing season begins.
For a comprehensive year-end bookkeeping checklist, DWG’s earlier post Year-End Bookkeeping Checklist for Small Businesses provides a detailed step-by-step guide.
Most discussions of internal controls for small business end with segregation of duties and bank protections. Few address the failure mode that shows up clearly in the data. The ACFE found that owners and executives accounted for 16% of cases in 2026, up from 12% in 1996, with losses rising sharply alongside the perpetrator’s position.
Owner override is usually not theft. It is the owner telling the bookkeeper to skip the approval this once because the deal is time-sensitive. It is a personal expense run through the business because it is simpler. It is a closed period reopened to improve a number before it goes to the bank.
Any single instance may be harmless. The cumulative effect is not. Every override signals that the control is optional and sets precedent for the next person who wants to bypass one. It also makes staff reluctant to question a transaction — the exact moment a business loses the tip that ACFE data identifies as its best detection method.
Controls are respected when leadership is visibly bound by them. That is the part of small business fraud prevention that costs nothing, and the part most often skipped.
Internal controls are not an expression of suspicion toward the people who work in the business. They are how a company stops depending on any single person’s continued good judgment, including the owner’s.
Darrell Groves holds the Certified Fraud Examiner (CFE) designation alongside his CPA and CGMA credentials, and control design is an area DWG CPA addresses directly with clients across construction, healthcare, professional services, and nonprofit organizations. An internal controls review documents where the weaknesses sit, tests whether existing controls work as designed, and produces a prioritized list the business can act on.
Most control gaps are straightforward to close once identified. What makes small business fraud prevention costly is the assumption that nothing has gone wrong because nothing has been noticed.
To review where your controls currently stand, schedule a discovery call.
If you’re building something important and need a trusted financial partner to grow with you – we’d love to hear from you.
77 Sugar Creek Center Blvd, Suite 600 Sugar Land, Texas, 77478
Copyright 2026 Designed & Developed by MYCPE ONE LLC. All Rights Reserved.