Opportunity, not sophistication
Almost every SME fraud is possible for the same reason: one person controlled a process end to end and nobody independent ever looked. The fix is design, not vigilance.
Almost every fraud we have seen in a UAE SME was possible for the same reason: one person controlled a process end to end, and nobody independent ever looked. Not sophistication — opportunity.
The controls that matter in a small team
Textbook segregation of duties assumes a finance department. Most owner-managed businesses do not have one, so the controls have to be designed for the team that actually exists.
| Risk | The practical control |
|---|---|
| Fictitious suppliers | New supplier bank details approved by someone other than the person who entered them, verified against a source the requester did not provide |
| Changed bank details | Any change to an existing supplier's bank details verified by callback to a known number — never to the number on the request |
| Unauthorised payments | Dual authorisation above a defined limit, with the limit low enough to matter |
| Cash and till losses | Counted and signed at shift change; banking evidenced against recorded takings rather than round sums |
| Stock loss | Counts performed by someone who does not control the stock records |
| Ghost employees | Payroll changes approved outside the payroll function; WPS file reconciled to the approved establishment list |
| Expense abuse | Approval by the budget holder, not the claimant's subordinate; receipts required regardless of amount |
| Owner override | The hardest one — an independent monthly review of the full ledger by someone outside the business |
Where an outside accountant genuinely helps
Not because we are cleverer, but because we are outside. An independent monthly close performed by a firm that does not report to the person being reviewed is itself a control — the single most valuable one available to a small business, because it is the only one that covers owner and manager override. The businesses that discover long-running frauds are almost always the ones where the person keeping the records also authorised the payments and prepared the reconciliations.
First: can one person in your business set up a new supplier and pay it, without anyone else seeing? Second: when did someone independent last agree your bank balance to your ledger, line by line? Those two questions find most of what there is to find.
Where a control failure has already caused a loss, the investigation and any recovery action is legal work and goes to Neo Legal.
Reviewed 18 August 2026 by Ahmed Nabil Selim. UAE tax rates, thresholds and deadlines change — confirm the position for your period before relying on it.
Internal controls — frequently asked questions
By separating the three things that must never sit together — recording transactions, authorising payments, and holding the assets — and by importing independence from outside for whatever cannot be separated internally. In practice that usually means the owner authorises payments and reviews bank reconciliations personally, an external accountant performs the close and reconciliations, and the person who handles cash or stock does not maintain the records for it. Perfect segregation is not available at that size; meaningful segregation almost always is.
Payment diversion in its various forms — fictitious or altered supplier details, and invoices for goods and services never received. It is common because it exploits the most frequent control gap: one person able to create a payee and release a payment. The related and equally common category is misappropriation of cash and stock in businesses that never reconcile takings to banking or count inventory independently. Neither requires sophistication; both require only that nobody independent looks.
Not reliably, and it is not designed to. A statutory audit gives an opinion on whether the financial statements are free from material misstatement — the responsibility for preventing and detecting fraud rests with management and those charged with governance. An audit may uncover fraud, particularly where it is large enough to be material, but a business relying on its annual audit as its fraud control has effectively no fraud control. Prevention is a controls question, not an audit question.
Is this your situation?
Tell us how the business is set up and where things currently stand. We will tell you what is required and what it costs to have it handled properly.
Talk to an accountant →