
Why employees ignore anti-fraud policies: The policy was signed, but the shortcut ran the company
At 7:42 Tuesday morning in Kampala, an internal auditor opened a routine supplier-payment report and noticed something that looked too neat to be accidental. Eleven invoices, processed over four months, ranged between UGX 9.6 million and UGX 9.9 million. The organisation required additional approval for purchases of UGX 10 million or more.
The invoices described different supplies, came from three apparently independent businesses and carried all the expected signatures. On paper, the anti-fraud policy was working. Every employee had signed it. Every payment had been approved. Every file had been stamped. Yet the goods were not in the warehouse.
When Summit Consulting Ltd was called in, management initially framed the matter as a possible procurement fraud. I cautioned them against beginning with a verdict. An investigation must start with a question, not a suspect. Fraud is an allegation until the evidence establishes what happened, who participated, how they participated and whether the conduct was dishonest or merely negligent.
The case presented here is an anonymised composite of recurring workplace patterns. The characters, figures and identifying details have been adapted for learning. The lessons, however, are painfully real.
The policy nobody could use
The first problem was language. The organisation’s anti-fraud policy prohibited “fraudulent, collusive, coercive, deceptive and irregular conduct intended to occasion pecuniary or reputational prejudice.” That sentence would impress a lawyer and confuse a storekeeper. It did not explain whether accepting fuel from a supplier, sharing a password with a colleague, changing a quotation after submission, dividing one purchase into smaller invoices or approving goods not physically seen amounted to prohibited conduct.
Legal precision matters, but precision is not the same as complexity. A useful policy tells an employee, in clear terms: “Do not split a purchase to avoid an approval limit. Do not approve goods you have not confirmed. Do not use another person’s account. Declare any personal relationship with a supplier.” Employees should not require legal counsel to recognise the boundary between an acceptable shortcut and misconduct.
The policy had also been communicated as an administrative event. Human resources emailed it on a Friday afternoon and required everyone to click “I agree.” Completion was measured; understanding was not. International law guidance is not Ugandan law, but it provides a useful effectiveness test: can employees find the policy, understand it, apply it to their work and obtain advice when facts are unclear? It also recommends training tailored to actual roles, risks and previous incidents, rather than generic annual presentations.
The third weakness sat in the conduct of leadership. The broad-shouldered operations executive routinely instructed staff to “regularise the paperwork later” whenever an urgent customer order arrived. He was not accused of participating in the suspected fraud. His language nevertheless taught the organisation that controls were negotiable when revenue, speed or hierarchy applied pressure. Employees do not learn culture from posters. They study what happens when a powerful person encounters an inconvenient rule.
The final weakness was structural. Management expected employees to follow the anti-fraud policy while rewarding them almost entirely for speed, cost reduction and monthly targets. The procurement officer who delayed a questionable transaction was described as obstructive. The officer who found a way around the delay was celebrated as commercially sharp. The organisation had written one rule and designed another into its incentives.
Here is your easy of use challenge:
Place a copy of your anti-fraud policy on the table. Give managers three minutes to find the answer to this question: “A supplier has delivered urgently, but the purchase order was not approved. May I backdate the documents so that finance can pay?” Do not allow the policy owner to explain it. If managers cannot locate a clear answer, the employee at the frontline will follow the loudest person in the room. Rewrite the relevant provision in fewer than forty words, then add the person to contact and the record that must be created.
The shortcut becomes the system
The slim procurement officer, always in a carefully pressed pale-blue shirt, had helped establish two of the suppliers. Company searches showed no obvious connection to him. The relationship emerged elsewhere. One supplier’s contact number had previously appeared as the emergency contact for a person living at the same address as the officer. That fact on its own proved nothing, but it justified further inquiry.
The scheme did not begin with a dramatic theft. It began with an operational exception. A manager needed materials urgently. The procurement officer obtained verbal permission to source them quickly, promising that the documentation would follow. The goods arrived and the customer order was completed. Everyone praised the result. A temporary workaround had been legitimised by success.
Over time, the officer submitted purchases just below the enhanced approval threshold. The soft-spoken finance supervisor with silver-rimmed glasses approved the payments. A warehouse clerk with ink-stained fingers prepared goods-received notes, sometimes several days after the recorded delivery date. The forms appeared complete because the control was being performed as handwriting, not as verification.
Money initially moved into the suppliers’ bank accounts. Smaller amounts were then transferred to mobile-money numbers registered to relatives, agents and casual workers. Cash withdrawals followed, often within hours. Some money was used for genuine supplies; some returned through cash and mobile-money transfers to people connected to employees. Investigators did not label every withdrawal a kickback. We reconciled each payment against bank statements, operator records obtained through lawful channels, delivery evidence, inventory movements and the supplier’s accounting records. Movement of money is evidence of movement, not automatically evidence of purpose.
The reporting channel failed at the moment it was most needed. A junior accounts assistant had noticed repeated payments below the threshold, but the policy told her to report to her immediate supervisor. That supervisor was involved in approving the transactions. She remained silent because the reporting design offered no independent route and no credible protection against retaliation. ISO 37002 grounds an effective whistleblowing system in trust, impartiality and protection, covering the receipt, assessment, handling and conclusion of reports. Uganda also has a statutory framework for public-interest disclosures in both private and public organisations, under the Uganda Whistleblowers Protection Act.
The auditor noticed the wrong kind of neatness
The internal auditor did not discover the matter through a confession. He noticed numerical behaviour. Legitimate transactions usually carry the untidiness of real operations: varying amounts, different delivery times, changing quantities and occasional corrections. These invoices repeatedly landed just below the same threshold. The amounts were individually plausible but collectively patterned.
He then compared the vendor master file with employee records, supplier telephone numbers, bank-account details, physical addresses and system-access data. Several weak signals began pointing in the same direction. A supplier email had been created shortly before its first tender. Three quotations contained the same spelling error. Two supposedly independent PDF quotations had been generated by the same software profile within minutes of each other. None of those facts proved authorship, but together they challenged the claim of independent competition.
The physical evidence was even more revealing. The warehouse forms recorded delivery of 240 units. The stock ledger showed 240 units received. The security gate register showed no vehicle entering at the recorded time, while production records reflected consumption of only 86 units. Investigators checked whether the balance could have been stored elsewhere, issued without recording or lost through poor stockkeeping. An investigation that examines only the theory of guilt is merely a prosecution memo wearing an investigator’s coat.
The junior accounts assistant eventually spoke after the investigation team created a confidential route outside management. She did not report theft. She reported words: “Use the same three suppliers. They understand how we work.” Her recollection provided direction, not proof. We looked for contemporaneous messages, meeting records and transaction patterns that could confirm or contradict it. Memory changes; records also have weaknesses. Reliable findings emerge where independent sources converge.
Building evidence that can survive challenge
The investigation team issued a preservation notice before interviewing the suspected employees. Email, procurement-system logs, access records, CCTV, vendor-master changes, mobile-device backups and relevant financial records were secured under documented authority. We defined the investigation period and custodians carefully. Collecting every personal message from every employee would have been excessive and potentially unlawful. Uganda’s Data Protection and Privacy Act requires personal-data processing to be adequate, relevant and not excessive or unnecessary.
Digital evidence was collected in its native form where possible. Screenshots were treated as leads because they can omit metadata, context and preceding messages. Investigators recorded the source, collector, date, time, method, device and storage location. Originals were preserved, analysis was performed on controlled copies, and cryptographic hash values were calculated close to collection. NIST advises early hashing and secure preservation of hash values because evidence or its recorded hash can otherwise be altered, deliberately or accidentally.
This preparation anticipated the obvious defence challenges. “Several employees shared the password.” “The IP address served the whole office.” “Anyone could have edited that spreadsheet.” “The mobile-money number belongs to my relative, not me.” “The goods may have arrived through another gate.” Those are not irritating excuses to dismiss. They are alternative explanations to test. A login record becomes stronger when supported by multifactor-authentication data, device identification, access-card records, transaction timing and a message discussing the same payment. An IP address alone rarely identifies the human being behind the keyboard.
The interviews were conducted after the documents had been studied. The slim procurement officer was allowed to explain each supplier relationship and challenged the allegation that he had benefited. The finance supervisor said she relied on the warehouse confirmations. The warehouse clerk said he signed because the procurement officer told him the goods had been delivered directly to production. Each account was checked against timestamps, stock movements, messages and independent witnesses. The investigators recorded both incriminating and exculpatory material. A fair investigation is not softness; it is what makes a hard conclusion credible.
Uganda’s Electronic Transactions Act places particular weight on authenticity, the reliability of the way an electronic record was generated and stored, identification of the originator, system integrity and the preservation of origin, destination, date and time. The courtroom lesson is simple: do not arrive with a printed email and confidence. Arrive with provenance.
Closing the case without creating another injustice
The investigation separated its findings into distinct categories. Some transactions were supported and properly received. Others reflected poor documentation without sufficient evidence of dishonesty. A third group contained unsupported deliveries, concealed relationships, irregular approvals and financial benefits that could be traced to connected persons. This distinction prevented the organisation from treating every control failure as fraud.
Employment action was also kept separate from criminal referral. An internal finding does not amount to a criminal conviction. Before reaching a dismissal decision for misconduct, Uganda’s Employment Act requires the employer to explain the reason under consideration in a language the employee can reasonably understand and hear the employee’s response. Dismissal for misconduct is reserved for serious misconduct or repeated disciplinary infringements. The organisation therefore issued specific allegations, disclosed the material relied upon, heard responses and documented why comparable cases received comparable treatment.
Leadership conduct was not ignored merely because senior managers had not received money. The executive who encouraged retrospective regularisation was counselled, approval exceptions were restricted and his performance measures were changed. Consistent enforcement does not require identical sanctions for different conduct. It requires a principled explanation of why responsibility, knowledge, intent, benefit, cooperation and previous conduct produced a particular outcome.
The policy was then rebuilt around the work. Procurement thresholds were monitored cumulatively rather than invoice by invoice. Supplier conflicts were declared and independently verified. Vendor-master changes generated alerts. Goods receipt required evidence from the receiving function rather than confirmation supplied by procurement. Analytics highlighted repeated near-threshold transactions, rapid supplier payments, unusual approval times and common identifiers across employees and vendors. Artificial intelligence may improve anomaly detection, but it must not declare guilt. It should identify transactions requiring human review, with explainable rules, protected data and tested error rates.
What leaders often miss
Why employees ignore anti-fraud policies is the wrong question when asked in isolation. The stronger question is: what does the organisation make easier, safer and more rewarding than compliance? A policy cannot compete with a chief executive’s instruction, an impossible deadline, an unprotected reporting channel or a system that permits one employee to create, approve and amend a transaction.
Policy effectiveness should be measured through behaviour. Track whether employees can locate relevant guidance, recognise realistic scenarios, seek advice before acting, report concerns safely and observe consistent management responses. A ninety-eight per cent policy-signing rate may simply mean that ninety-eight per cent of employees clicked a button.
Boards should also examine near misses, overrides, conflicts declared, reports closed, retaliation allegations, repeat control failures and the time taken to investigate concerns. ISO now provides guidance for fraud control management systems through ISO 37003:2025 and for internal investigations through ISO/TS 37008:2023. These standards reinforce an important shift: fraud risk must be managed as a living system, not a document owned by compliance.
The deepest lesson is not that employees are untrustworthy. It is that good people adapt to the environment placed around them. If leaders repeatedly bypass controls, employees will learn the choreography. If reporting is dangerous, silence will look rational. If enforcement depends on rank, the policy will become ceremonial.
In this composite case, the investigation substantiated a total quantifiable loss of UGX 486,740,000. The money did not escape because the organisation lacked an anti-fraud policy. It escaped because purchases were divided below approval limits, supplier relationships were not independently checked, warehouse confirmations were accepted without physical verification, passwords and responsibilities were blurred, reporting routes were unsafe, and leadership had normalised retrospective paperwork.
The policy had not been defeated. It had never entered the real operating system of the organisation.
Copyright Institute of Forensics & ICT Security, 2026. All rights reserved.


