In brief: Fraud is not mainly a big-company problem. Dollar for dollar, the organisations hurt worst are small ones — and the single control that catches fraud most often is the one they are least likely to have. The good news is that closing the gap does not take a corporate integrity department; it takes a few things that matter, sized for your business.

Most business owners picture fraud as a big-company problem — a rogue trader in a bank, a nine-figure scandal in the news. The data says almost the opposite. The organisations that get hurt worst, dollar for dollar, are the small ones.

The most reliable picture we have comes from the Association of Certified Fraud Examiners (ACFE) and its Report to the Nations — the largest study of real, investigated occupational fraud in the world, built from 2,402 real cases across 143 countries. The figures below are drawn from its 2026 edition. A few of them should stop any owner in their tracks.

Small businesses carry the biggest relative loss

Organisations with fewer than 100 employees record a median loss of around US$126,000 per case — among the highest of any size band, and landing on exactly the businesses least able to absorb it. A large corporation can wear a six-figure hit. For a family business, it can mean redundancies, a personal guarantee called in, or the doors closing.

Why are the small ones hit hardest? It is structural, not bad luck. Small and family businesses run on trust rather than controls. One long-tenured, well-liked person ends up holding the books, the passwords and the payments, and no one revisits that arrangement — because doing so would feel like an accusation. The ACFE data bears this out: only around 24% of small organisations have a fraud-reporting hotline, against roughly 85% of larger ones. Fewer run fraud training or have any internal audit function at all. That low-control environment is precisely where cheque and payment tampering, skimming and false-billing schemes quietly take hold.

The longer it runs, the worse it gets

The single biggest factor in how much a fraud costs is not how sophisticated it is — it is how fast it is caught. The typical scheme runs about 12 months before anyone notices. Caught within six months, the median loss is modest. Left to run for five years or more, median losses climb past US$1.1 million. Time is the multiplier.

It is the tip, not the audit

Here is the finding that surprises owners most. The external audit that many treat as their safety net catches only about 3% of frauds. The single most effective way fraud comes to light is a tip — around 43% of cases, nearly three times any other method — and more than half of those tips come from employees. In other words, your people usually see it first. The question is whether they have somewhere safe to say so, and someone independent on the other end who will act.

What actually protects a business

You do not need to build a corporate integrity department to close the gap. You need the few things that matter, sized for your business:

  • A confidential reporting channel your people trust enough to use — the control the data says works best, and the one small businesses most often lack.
  • Someone independent to triage and investigate what comes in, quickly, before the trail goes cold.
  • A periodic look at the obvious exposures — fraud, theft, conflicts of interest, procurement and payroll.

That is the logic behind a retained integrity function: the parts of a corporate fraud-control program that genuinely move the needle, without the headcount. If you would like to see where your business is exposed — and what the evidence would actually support if something surfaced — you can start with a confidential conversation.

Figures: ACFE, Report to the Nations 2026 (global data, reported in USD).