Corporate fraud begins inside the process.
A detailed guide to internal misconduct, payment diversion and the evidence trails that matter to Australian boards, legal advisers and investigators. The truth has a trail.
Internal risk is visible in disclosures, decisions and records.
Australia has no single, reliable public estimate of total fraud inside private businesses. The available sources still show where governance and investigation can fail.
In its December 2025 review, ASIC analysed responses from 134 selected companies. Those companies reported 8,095 disclosures through designated whistleblower channels during July 2024 to June 2025. On average, companies assessed 39% of disclosures as within the legal whistleblower framework. Among investigated in-scope matters, companies reported an average substantiation rate of 24%. Each percentage uses a different company-level denominator; they cannot be multiplied into a national case count. [14]
ASIC's questionnaire responses were self-reported, not independently verified and not statistically representative of all Australian companies. Some responses included employees outside Australia. Disclosures include matters other than fraud; 8,095 is not a tally of proven fraud cases. [14]
Follow the transaction and the authority trail.
These are investigative typologies, not estimates of scheme frequency. A useful case theory identifies who could act, what changed, what was approved and what independent evidence can test the explanation.
Changed destinations
Join supplier onboarding, invoices, bank-detail amendments, mailbox rules, call-back records, approval limits and actual transfers. A compromised mailbox and an insider-enabled change can look similar until the access and authorisation history is tested. Payment redirection was associated with $166.8 million in combined reported scam losses in calendar 2025. That national scam figure is not a measure of internal corporate fraud. [1][3]
Conflicts and contracts
Preserve tender versions, scoring sheets, conflict declarations, communications, beneficial ownership clues and post-award variations. Test whether an apparent commercial judgement was shaped by undisclosed relationships or altered criteria. Commonwealth guidance identifies control points across the procurement lifecycle. [8]
People and time
Reconcile employee creation, identity records, rosters, timesheets, allowances, leave, payroll edits and bank-account changes. Follow who submitted and who approved each exception. Differences are leads to investigate; they are not findings by themselves.
Cards and claims
Compare original receipts, merchant data, transaction dates, policy exceptions, business purpose and relationships between claimants and approvers. Repeated small exceptions can reveal a control pattern even when each item looks routine.
Stock and write-offs
Trace custody from purchase to disposal. Test returns, damaged stock, serial numbers, inventory adjustments, physical counts and write-off approvals. A missing asset is an observation; responsibility requires a supported chain of access and events.
Management override
Review journal permissions, timing, manual entries, supporting contracts, reconciliations and reviewer challenge. Separate an accounting judgement from deliberate misstatement through contemporaneous records and alternative explanations.
A quiet channel is an ambiguous signal.
ASIC found that 58% of surveyed companies had not sought employee feedback on their whistleblower programme, 30% did not regularly review its effectiveness and 25% did not provide regular staff training. Those figures describe responses from a selected sample; they do not measure how much fraud occurred. [14]
A low disclosure count may indicate low misconduct, poor awareness, lack of trust or a route outside the designated channel. Boards need context: awareness, access, case age, substantiation, protection and remediation.
Can staff and third parties report safely? Who can see an allegation about a senior leader? How quickly can volatile records be preserved? Are cases triaged by a documented standard? Are findings and control repairs tracked separately?
The original disclosure should be preserved with restricted access. Intake should distinguish a personal grievance from potentially protected whistleblower information and identify urgent evidence risks. Legal advice may be required on protections and obligations in a specific matter. [14]
Make the finding defensible.
The quality of the conclusion depends on how the evidence was collected, tested and explained.
Open-source intelligence can suggest relationships or contradictions, but a profile or search result is not proof. Preserve native digital records, timestamps, time zones, provenance and access history. ASD's incident-response guidance calls for documented evidence collection and handling, including dates, people, locations and hash values where appropriate. [13]
- Define the allegation. Set the people, period, systems, potential loss and decision points.
- Protect the record. Preserve mailboxes, logs, approvals, source documents and relevant devices proportionately.
- Test alternatives. Reconcile transaction data with interviews, system history and innocent explanations.
- Provide procedural fairness. Put material adverse evidence to the affected person where appropriate.
- Close the loop. Distinguish unsubstantiated from disproven; document the standard, reasons and control remediation.
Do not turn disclosure data into a fraud rate.
ASIC's selected-company disclosures, the Australian Institute of Criminology's Commonwealth entity allegations and the National Anti-Scam Centre's reported scam losses measure different populations and events. They cannot be summed or treated as a private-sector fraud denominator. [1][6][14]
The Australian Institute of Criminology recorded 14,323 internal fraud and corruption allegations received or detected by Commonwealth entities in 2024–25. They are allegations within government entities, not proven cases and not a measure of private business. [6]
For the definitions, all 14 primary sources and reading limits, read the Index methodology and source notes.
Read the full 2026 Index.
22 pages, including the four-page corporate chapter and linked source notes.
Sceáwian Intelligence Group analysis of published data, 28 September 2026. General research, not a finding about any organisation or legal advice.