How Corporate Governance Failures Create the Conditions for Fraud
Article
26.08.2026
11 minutes

How Corporate Governance Failures Create the Conditions for Fraud

When fraud is uncovered, attention usually turns to the person responsible. Who committed the offence? How did they do it? Who helped them? Which rules did they manage to circumvent? These questions matter, but answering them does not necessarily prevent the same thing from happening again.

The more revealing questions concern the decisions made higher up the organisation. Who approved the product, process or incentive scheme that created the opening? Who assessed the risk before launch? What information failed to reach the executives who could have intervened?

Elina Moshkovich, an international expert in GRC, risk management and fraud prevention, sees fraud as more than individual misconduct. It can also be a sign that the governance system itself is not working as it should. The greatest danger arises when that system makes abuse easy to initiate, profitable to scale and difficult to detect.

Corporate Governance Is More Than an Organisational Chart

From a fraud risk perspective, corporate governance is the way decisions are actually made. Formal reporting lines are only part of the picture. What also matters is who takes part in the discussion, which information reaches management, who can vote or exercise a veto, and which issues never reach the board or relevant committee at all.

This is what determines which risks an organisation notices and which remain out of sight. Some options are debated openly. Others are removed before a meeting even begins. Some warning signs are escalated quickly, while others are softened, delayed or lost as they move through the organisation.

Nine closely connected elements shape the governance system: business strategy, organisational structure, operating model, roles and responsibilities, committees, communication, corporate culture, incentives and remuneration, and internal control. A weakness in any of them can create the conditions for fraud.

Internal control cannot be separated from the other eight. Control procedures will struggle if accountability is unclear, incentives reward risky behaviour or control functions do not have access to the full picture. No set of controls can make up for fundamental weaknesses in the way the organisation is governed.

Four Common Governance Failures

Four weaknesses appear particularly often in companies where fraud has been able to take hold.

The first is conflict of interest. A function that is expected to assess risk independently may report to the very business unit pushing for a quick commercial result. In that structure, an unwelcome conclusion is much less likely to reach senior management without being softened or reframed.

The second is unclear accountability. Responsibility may be spread across several functions, with no single team clearly owning the risk or the control. Warning signs are easily lost in these grey areas, and decisions are repeatedly postponed.

The third is information asymmetry. The board or relevant committee may see an edited version of events rather than the underlying reality. When information travels through one channel, is reduced to a short management summary and arrives without supporting data, the opportunity to intervene may already have passed.

The fourth is poorly designed incentives. A remuneration scheme may reward volume, speed or growth without accounting for sales quality, policy persistency, loss ratios or customer complaints. The company then finds itself investigating the very behaviour it has encouraged.

Aggressive targets do not automatically turn employees into fraudsters. The problem is more subtle. A badly designed system can make misconduct easier, more rewarding and less visible than doing the job properly.

Two anonymised cases show how very different losses can have much the same governance failure behind them.

Case 1. A Product with Risk Built into Its Design

The first case involved an insurance product offering life and critical illness cover, with an additional benefit for Group III disability. The company was under pressure after missing its commercial targets and wanted a product that could lift sales quickly.

Management reviewed the market, competing offers and customer demand. The resulting product differed significantly from existing alternatives and was brought to market on an accelerated timetable. All the relevant functions formally approved it, including risk management, compliance and fraud prevention.

The problem emerged later, when claims for Group III disability began to rise sharply. Many of the reported symptoms were difficult to verify objectively. These included impaired vision or hearing and persistent headaches following road accidents. The product created room for abuse, including staged accidents and organised fraud.

Proving that individual claims were fraudulent was extremely difficult. In some cases, investigators uncovered relationships that made the enquiries even more complex. The risk committee eventually stopped further sales, but the financial consequences continued to surface for several years.

How did a formally approved product create such substantial exposure?

Part of the answer lay in the reporting structure. The head of product development reported to the head of sales. Commercial pressure and the need to launch quickly carried more weight than an independent view of the risk. The product never received a sufficiently rigorous independent assessment, and medical specialists were not involved when their input could still have influenced its design.

There was another warning sign. The company chose not to impose geographical underwriting restrictions. Higher-risk territories remained within the product’s scope because excluding them could have reduced gross written premium.

Case 2. When KPIs Create the Conditions for Fraud

The second case also involved an insurance company, but this time the weakness lay in the incentive scheme. Management wanted the agency network to grow faster.

Under a traditional agency model, remuneration depends on productive business and policy renewals. It generally takes between six and twelve months for an agent to become established. The model provides a natural filter: unproductive agents gradually leave, while the network grows around a more sustainable portfolio.

The new programme replaced that filter with a faster reward structure. During the first six months, agents received fixed remuneration for completing training and making ten sales. From months seven to twelve, payment depended on twenty sales and the recruitment of three new agents. The company piloted the scheme in four regions.

The stated objective was faster growth in the agency network. What grew faster in practice were losses from fraud and mis-selling.

Within six months, the results had diverged sharply from those of the traditional agency channel. Cancellation rates during the free-look period were ten times higher. The number of fraud cases per agent had doubled. Complaints about mis-selling in the pilot regions were more than three times higher than in other channels.

The problem was built into the KPIs. Agents were rewarded for the number of policies sold and people recruited, but not for policy persistency, loss ratios, customer complaints or the outcome of checks after the free-look period. Payments were made before the company could properly judge the quality of the business.

Agents had a financial incentive to build volume quickly, even where the policies did not meet customers’ needs or contribute to a sustainable portfolio. The recruitment target added a pyramid-like dynamic. People were brought in to satisfy the target rather than to develop a capable agency network.

A conflict of interest drove the first case. A flawed incentive structure drove the second. But the underlying failure was the same: the governance system did not identify and escalate the risk while there was still time to change the decision.

The Three Lines Model Depends on Clear Roles

Many financial institutions organise their control functions around the three lines of defence. The first line consists of the business and process owners. Risk management, compliance and fraud prevention sit in the second line. Internal audit forms the third.

The model becomes less effective when responsibilities overlap, are duplicated or remain unclear. The risk is greater when a second-line function effectively reports into the first line, as happens when risk management sits within a commercial division.

Specialists may recognise the danger, but their conclusions never reach the executives with the authority to stop a launch, change the KPIs or redesign the process. The control exists on paper but does not influence the decision.

Reporting lines alone are not enough. The real test is authority. Who can stop a product launch? Who can see the original data and customer complaints? Who can report directly to the board without the message first passing through a management filter?

What Management Should Review

A practical review of corporate governance can begin with four areas.

The first is the independence of control functions. Management needs to examine the reporting lines for risk management, internal audit, compliance and fraud prevention. If the function assessing risk sits inside the business line it is expected to oversee, its independence is already in doubt.

The second is the incentive structure. KPIs for commercial, product and distribution teams need to be judged by the behaviour they produce, not simply by how they are worded. If a metric rewards volume and speed while ignoring quality, the company is creating an incentive for abuse.

The third is the flow of information. Management can trace a recent material risk signal from the moment it appeared to the point when it reached the board or relevant committee. Who saw it first? Who interpreted it? How did the wording change along the way? Did the decision-makers receive the underlying data?

The fourth is the allocation of accountability. After a serious incident, the question is not only who committed the misconduct. Management also needs to identify which part of the governance system had no clear owner. Was anyone responsible for the control? Did that person have enough authority? Was there a clear and independent escalation route?

Questions like these move the discussion beyond the investigation itself and towards management accountability. That is often where the real cause of systemic fraud lies.

Fraud as a Warning Sign of Governance Failure

No governance system can prevent every instance of fraud. A well-designed system can, however, make it much harder for misconduct to continue unnoticed or grow to a significant scale without producing warning signs that can be seen and tested.

An investigation should therefore not end when the responsible individuals have been disciplined and the incident formally closed. Every material case should prompt a review of the decisions, authority structures, incentives and information flows that allowed it to happen.

Otherwise, the company will continue searching for new offenders while leaving intact the conditions that enabled the previous ones.

Anti-fraud under resource constraints: how to identify risk convergence points
Anti-fraud under resource constraints: how to identify risk convergence points
#Anti-Fraud, #Risk Management

How banks can build effective anti-fraud systems when resources are insufficient for total control. Why, in such conditions, the number of checks matters less than precise prioritization, the ability to separate noise from real risk, and the discipline to identify where fraudulent activity converges. What measures strengthen protection without heavy infrastructure: monitoring dormant accounts, limiting remote onboarding, analyzing links between transactions, and involving employees beyond the anti-fraud function.

Internal Communication as a Driver of Team Performance
Internal Communication as a Driver of Team Performance
#Delegation, #Emotional Intelligence, #Employee Engagement, #Internal Communication, #Leadership, #Organisational Development, #Team Performance, #Workplace Culture

Internal communication is not simply the exchange of information. It shapes how employees understand objectives, make decisions, delegate work, resolve disagreements and build trust. Aigul Sandalova explains how managers and employees can communicate more clearly, manage emotions and reduce the misunderstandings that undermine team performance.

Similar articles

How to Build a Mature Anti-Fraud Function
#AML #Anti-Fraud #Banking Risk #Compliance #Financial Crime #Fraud Analytics #fraud prevention #Fraud Risk Management #Operational Risk
How to Build a Mature Anti-Fraud Function

Fraud schemes often evolve faster than internal controls. A mature anti-fraud function does more than investigate losses. It identifies weaknesses early, informs product design, connects signals across accounts and measures whether controls are reducing risk without creating unnecessary friction.

Risk Management as Part of Decision-Making
#Board of Directors #Corporate Governance #Enterprise Risk Management #Operational Efficiency #Risk Management #Strategy
Risk Management as Part of Decision-Making

Policies, risk registers and risk committees do not necessarily mean that a company is managing risk. The system begins to add value when it helps to take better decision before a mistake becomes irreversible. This article looks at how to connect risk with business objectives, involve the risk function earlier and turn indicators into management action.

Fraud in fintech: the price of convenience
#Antifraud #Artificial Intelligence #Digital Services #Fintech #Operational Efficiency #Risk Management
Fraud in fintech: the price of convenience

Fraud in fintech is no longer just a security concern. It shapes growth, trust and regulatory scrutiny. This article explores the trade-offs between convenience and control, what works in practice, and how risk strategy evolves as companies mature.

Operational Efficiency in China: Turning a Business Tour into a Management Project
#Automation #Business Tours #China #Digitalisation #Industrial Benchmarking #Manufacturing Processes #Operational Efficiency
Operational Efficiency in China: Turning a Business Tour into a Management Project

A visit to one of China’s leading manufacturers can easily become little more than an impressive factory tour. Executives see robotic production lines and digital dashboards, take photographs and then return to the same problems and ways of working. For a business tour to deliver real value, the focus needs to be on the processes, performance measures and management decisions behind the technology.