पाठशाला Pathshala · संचालन Sanchālan, Operations · Lesson 17 · Build
Internal controls and the fraud you did not expect
Most startups that lose money to fraud lose it through payments one person could make alone, vendors nobody checked and refunds nobody approved. Fifteen controls close those leaks, and they cost little if installed before the leak.
Pathshala, The Founder Library · 11 October 2026 · 7 min read

The fraud that hits a young company is almost never sophisticated. A trusted person could create a payment and release it. A vendor was added without anyone checking whose bank account it was. An email asked for this month’s payment to go to a new account, and it did. The controls that would have stopped each of these cost an afternoon to install. They cost a great deal more to install afterwards.
This lesson sets out where money leaks out of startups, the one control that does the most work, the controls on vendors, expenses, payroll and money coming in, why no outsider is likely to test any of this for a private company, the human controls that catch what the systems miss, and a monthly review. A tickable register of fifteen controls sits in the middle.
Where the money leaks
The Association of Certified Fraud Examiners publishes the largest regular study of fraud committed by people inside organisations. Its 2026 Report to the Nations draws on 2,402 cases from 143 countries and territories, and its headline finding for a founder is that the presence of anti-fraud controls is associated with lower losses and quicker detection. Among the behavioural warning signs it tracks, an unusually close association with a vendor or customer carried a median loss of $300,000, and a refusal to take holidays $250,000. Both are signs a company can watch for, and both point at the same places.
In a startup the leaks cluster in six places. Payments: one person with the power to create and release a bank transfer. Vendors: a shell vendor owned by an employee or a relative, an inflated invoice with a kickback, a duplicate invoice paid twice. Bank-detail changes: an email, often from a compromised vendor mailbox, asking that payments go to a new account. Expenses and cards: personal spend on a company card, split bills to stay under a limit, reimbursements for the same cost twice. Payroll: a leaver who stays on the payroll, a salary changed outside the cycle. Money coming in: refunds and credit notes to friendly accounts, and, in businesses with field staff or stores, collections taken into personal UPI handles. None of these needs skill. Each needs only that one person can act alone and nobody looks.
Maker and checker: the control that does the most
The principle is old and simple: no single person can both create a transaction and approve it. In the bank it means separate maker and authoriser roles on the corporate net-banking login, set up with the bank at the start, rather than one founder login that can do everything. In the accounting software it means the person who enters a vendor invoice is not the person who approves it for payment. In the vendor master it means the person who adds a vendor is not the person who approves that vendor’s invoices. Add two refinements. Any payment above a fixed amount needs a second authoriser, and the first payment to any new payee needs a founder, because that is where diverted payments begin. And pay vendors in a fixed weekly run from approved invoices only: an urgent payment outside the run, requested by someone senior over WhatsApp, is the commonest shape a fraudulent payment takes.

Maker and checker applies to founders too. A founder who can create and release payments alone is a single point of failure even if perfectly honest, because their credentials can be stolen and their inbox impersonated. The rule that binds everyone else must bind them, or it binds nobody.
The vendor master and the bank-detail change
Every rupee paid out goes to someone in the vendor master, so the master is where controls do the most good. Onboard each vendor with its PAN, its GSTIN checked on the GST portal for status and legal name, and its bank account verified by a small test transfer or a cancelled cheque in the vendor’s own name. Have one person onboard and a different person approve. Once a month run a duplicate check: vendors sharing a PAN, a bank account, an address or a phone number with another vendor or with an employee. Collect a related-party declaration once a year from everyone who can approve spend. A vendor owned by a relative is not wrong in itself; one that nobody disclosed is how most kickback schemes start.

Treat any request to change a vendor’s bank details as suspect until proved otherwise. The rule is mechanical: no change is made on the strength of an email, a letter or a message, however genuine it looks. The finance team calls the vendor on a number already on file, not one in the request, confirms the change, records who confirmed it, and pays a small test amount before the next real payment.
Expenses, payroll and money coming in
Write a one-page expense policy with limits by category, issue company cards with per-person limits, and require receipts within a week. The approver is the claimant’s manager; founders’ claims go to the other founder or the finance head. Review card spend monthly for the patterns that matter: amounts just under a limit, bills split across two claims, round numbers, weekend spend, the same merchant every week. Payroll needs one reconciliation a month: headcount on the payroll against the HR system and against the PF and ESIC filings. A name that appears on one list and not the others is either an error or a ghost, and either one costs money every month it stays.
Controls on cash coming in are the ones founders forget, because the leak looks like customer service. Every rupee from customers lands in a company bank account or gateway; no member of staff ever collects into a personal UPI handle or displays a personal QR code, whatever the convenience. Credit notes, refunds and discounts above a limit need approval from someone other than the person who raised them. Gateway settlements and bank receipts are reconciled to invoices every day, as the [bookkeeping lesson](/library/bookkeeping-from-day-one) describes, and receivables are aged every week, because unapplied cash and quiet write-offs are where diverted collections hide.
Fraud in a young company needs no skill. It needs only one person who can act alone and nobody who looks.
Why nobody else will test this for you
Founders often assume the statutory auditor checks controls. For most private companies the auditor is not required to. Section 143(3)(i) of the Companies Act asks the auditor to report on the adequacy and operating effectiveness of internal financial controls, but an MCA notification of 13 June 2017 exempts a private company with turnover under ₹50 crore or borrowings under ₹25 crore, provided it has filed its financial statements and annual return on time, as DPNC’s note on the exemption explains. One control the auditor does report on regardless: whether the accounting software kept an audit trail of every transaction through the year and whether it was tampered with, a requirement in force for financial years from 1 April 2023 and explained in the ICAI’s journal. The responsibility for the books themselves sits, under section 128(6), with the managing director, the director in charge of finance, the CFO or the person the board has charged with the duty. In most startups that is a founder.
The human controls
Systems catch what they are designed to catch. Four habits catch the rest. Mandatory leave: everyone who handles money takes a continuous week off each year, and someone else does their job that week; schemes that need daily tending surface when nobody tends them. Rotation: the person who reconciles the bank changes every year. Surprise checks: once a quarter a founder picks ten payments at random and traces each to an approved invoice, a delivered service and a verified vendor. A channel: a way for anyone in the company, or any vendor, to report a concern to someone outside finance, such as an independent director or the other founder, without it passing through the person concerned. The ACFE report finds web forms and email are the most common ways tips are made; a simple form is enough.
The monthly controls review
On the day after the monthly close, the finance lead sends the founders one page. New vendors added, and who approved each. Bank-detail changes made, with the name of the person who confirmed each by phone. Payments above the threshold, and their two authorisers. Credit notes and refunds above the limit, and their approvers. Payroll, HR and PF headcounts, and any difference. The audit trail’s edit log for entries changed after the period was closed. A founder reads it the same day and signs it. Once a year, before the audit, the board reviews the register above and records that each control operated. It takes an hour. It is the cheapest insurance the company will ever buy.
Nothing here is legal, tax or investment advice. Legal provisions are stated as checked on 11 October 2026; a chartered accountant should confirm which apply to your company.
Sources
- Association of Certified Fraud Examiners, Occupational Fraud 2026: A Report to the Nations
- DPNC, Note on Internal Financial Controls exemption for private limited companies (MCA notification G.S.R. 583(E), 13 June 2017)
- The Chartered Accountant Journal (ICAI), Audit Trail: Requirements and Responsibilities
- Companies Act, 2013, section 128: Books of account to be kept by company