A credible employee-fraud concern calls for a controlled first response—not an accusation. Use this checklist to protect records, organize verified facts, and decide when qualified legal, HR, forensic-accounting, insurance, cybersecurity, or law-enforcement help is needed.
This checklist is educational and is designed for administrative control. It is not legal, employment, forensic-accounting, insurance, cybersecurity, or law-enforcement advice. A red flag is not proof of misconduct. Preserve neutrality and obtain qualified advice before taking action that could affect an employee’s rights, privacy, pay, access, or employment.
First 24 hours: stabilize the situation
- Record the concern in neutral language. Capture who reported it, when it was reported, what was observed, and which transactions or records are involved. Avoid conclusions such as “stole” or “committed fraud.”
- Preserve records before they change. Secure relevant accounting exports, bank records, invoices, approvals, emails, access logs, payroll records, expense reports, contracts, and source files in their original form where practical.
- Protect ordinary operations. Identify imminent payment, payroll, cash, inventory, data, or safety risks. Use counsel-approved temporary controls when needed rather than making an unsupported public accusation.
- Notify the right advisers. Consider employment counsel, the company’s insurer, HR support, forensic accounting, cybersecurity specialists, or law enforcement based on the facts and policy requirements.
- Start a decision log. Record each preservation, access, notification, and review decision, including who approved it and why.
1. Open a neutral intake record
Create a case identifier and record the original allegation or anomaly as received. Note the source, date, affected period, accounts, vendors, employees, locations, and systems. Separate firsthand observations from hearsay. Preserve the original report rather than rewriting it to fit a theory.
- Case ID, date opened, intake owner, and source of concern
- Exact allegation, transaction, variance, or control exception
- People, systems, accounts, vendors, and periods potentially affected
- Immediate financial, operational, privacy, safety, or evidence risks
- Known facts, unverified statements, and open questions kept separate
2. Set independence and confidentiality boundaries
Assign an inquiry lead who is not implicated in the allegation and does not own the questioned activity. Limit case information to people with a legitimate need to know. Document conflicts of interest and escalation paths. Do not promise absolute confidentiality; explain that information will be handled as carefully as the process permits.
3. Build an evidence-preservation and custody log
List each record source before collecting files. Keep originals unchanged where practical, work from copies, and document who collected, transferred, reviewed, or exported each item. For electronic records, preserve available metadata and record the export method. Get qualified guidance before accessing personal devices, private accounts, employee communications, or other restricted information.
| Evidence item | Source and period | Collected by / date | Storage location | Integrity note |
|---|---|---|---|---|
| Example: vendor payment export | Accounting system, Jan–Aug 2026 | Owner / date | Restricted case folder | Read-only export; original retained |
| ________________ | ________________ | ________________ | ________________ | ________________ |
4. Create a transaction chronology and case log
Put events in date order: transaction creation, approval, payment, access changes, supporting-document changes, explanations, and follow-up. Link every important statement to its source record. A useful chronology shows what happened, what is supported, what conflicts, and what still needs verification.
- Date and time of the event or transaction
- Person, account, system, vendor, and amount involved
- Source document or evidence reference
- Control expected and control actually performed
- Explanation received and corroborating evidence
- Reviewer, conclusion status, and next action
5. Prepare interviews from the evidence
Review records first and prepare open, non-accusatory questions. Start with process and role questions, then move to specific documents and inconsistencies. Use qualified employment or legal guidance to decide interview order, attendance, notice, recording, and documentation requirements.
- Define the facts each interview should clarify.
- Prepare the relevant records and a clean question outline.
- Record who attended, the time, and the interview conditions.
- Distinguish direct answers, estimates, and follow-up commitments.
- Preserve the interview notes and link follow-up evidence to the case log.
6. Apply escalation boundaries
Pause the internal review and seek qualified help when the matter involves possible criminal conduct, threats, retaliation, privileged communications, regulated or personal data, cross-border information, significant financial exposure, insurance notice, unsafe conditions, executive conflicts, or a need for forensic imaging. Document why the escalation was made and who authorized it.
7. Record findings without overstating them
For each issue, state the question, evidence reviewed, facts supported, contrary evidence, unresolved limitations, and conclusion. Use calibrated terms such as “supported,” “not supported,” or “inconclusive” under the advice of qualified professionals. Keep the investigation conclusion separate from employment, legal, insurance, recovery, control-remediation, and reporting decisions.
8. Close the case and track remediation
- Approve and retain the final decision record.
- Document authorized personnel, legal, insurance, recovery, or reporting actions.
- Identify the control gap that allowed the concern to arise or remain hidden.
- Assign remediation owners, deadlines, evidence, and independent follow-up.
- Preserve the case file according to counsel-approved retention requirements.
- Schedule a post-case review without disclosing restricted case details.
What not to do
- Do not accuse, confront, search, suspend, terminate, or report a person based only on a red flag.
- Do not alter originals, ask witnesses to coordinate stories, or add conclusions to source records.
- Do not use shared case folders or discuss the matter with people who lack a need to know.
- Do not access personal devices, accounts, or communications without proper authority and guidance.
- Do not delay required insurer, regulator, safety, privacy, or law-enforcement consultation.
Small-business fraud investigation control sheet
Use your browser’s print dialog to print this control sheet or save it as a PDF. No email is required. Record completion, owner, date, evidence reference, and exceptions in your working records.
- ☐ Neutral intake record opened
- ☐ Immediate operational and evidence risks assessed
- ☐ Inquiry lead and conflicts documented
- ☐ Confidentiality and access boundaries set
- ☐ Evidence inventory and custody log started
- ☐ Accounting, bank, payroll, email, and access records preserved as applicable
- ☐ Transaction chronology and open-question log created
- ☐ Interview plan reviewed with qualified support when needed
- ☐ Escalation and notification duties evaluated
- ☐ Findings tied to evidence and limitations recorded
- ☐ Decisions approved and documented separately
- ☐ Remediation owners, dates, and validation evidence assigned
- ☐ Retention and restricted-access requirements confirmed
Use the Small Business Fraud Toolkit.
The toolkit includes red-flag checklists, a risk-and-control workbook, evidence-organization tools, and factual question prompts for planning next steps.
Related small-business fraud resources
- Employee fraud and embezzlement red flags
- Fraud case documentation checklist
- Small-business fraud prevention controls
Helpful references
- ACFE Occupational Fraud 2026: Report to the Nations
- ACFE Fraud Prevention Check-Up
- FTC resources for small businesses
Last reviewed September 5, 2026. Educational information only; not legal, HR, forensic-accounting, insurance, cybersecurity, or law-enforcement advice.