Fraud in real life rarely looks like a thriller.
It looks like a workaround.
A rushed supplier setup. A bank change done by email. A manual override that becomes “the process”. A month-end journal posted because everyone’s tired and the close has to land.
None of it starts with a villain.
It starts with pressure and a bypass that nobody owns.
This week’s issue is a practical playbook for spotting those bypass patterns where money moves, and for talking about them in a way leaders actually act on. Not policy. Not theatre. Decisions, exposure, and fixes that change behaviour.

1) Our Reality
Most organisations don’t have “no controls”.
They have controls that create work without changing outcomes.
So people route around them.
Sometimes that’s harmless.
Sometimes it’s the start of a loss.
This is why fraud prevention is not just about tighter controls.
It’s about better control placement.
A control that doesn’t protect a decision is admin.
Admin gets bypassed.
2) The Bypass Map: a simple framework
Use this framework to plan any fraud-focused review in finance.
The Bypass Map (4 lenses)
Money path
Where can money be created, moved, approved, released?Master data
Who can create or change the data that controls the money path?Overrides
What exceptions exist, how often are they used, who reviews patterns?Close pressure
Where does timing create “just post it” behaviour?
If you cover these four, you’ll usually find the real risk faster than a traditional control checklist.
3) The practical hotspots (what to test and why)
Here are the places I’d start, with the bypass to look for.
P2P
Vendor creation fast-tracked
Bank details changed outside workflow
Invoice splitting to dodge approval
Aged open POs and GRNI “parking”
O2C
Credit notes used as clean-up tools
Refunds approved without independence
Manual pricing overrides with weak reason codes
Poor cash allocation practices
Expenses and payroll
Repeat claims, same approver patterns
Starters/leavers changes without dual control
R2R
Manual journals late in close
Same preparer and approver
Posting into “quiet” accounts no one questions
You don’t need to test everything.
You need to test where the bypass lives.
4) The Control Bypass Interview (script you can reuse)
If you do one thing differently this week, do this.
Run a 20-minute bypass interview with the process owner.
Ask:
What happens on the busiest day of the month?
Which steps are “optional” when you’re under pressure?
Where do you rely on email, spreadsheets, screenshots?
What’s your emergency process and how often is it used?
Who reviews trends in overrides, not single cases?
Listen for:
“We don’t really do that”
“It’s meant to be…”
“We’re planning to fix it”
“It’s only temporary”
Temporary is where bypass hides.
5) Talk about decisions, not breaches
This is the profession shift happening right now.
Internal Auditors are becoming strategic partners, not compliance police.
That means your output needs to change.
Instead of:
Control did not operate.
Use:
Money can move without a clear decision here
Then present two options:
Option A: small redesign that changes behaviour
move control to the decision point
automate low risk flow
escalate exceptions
log reasons
Option B: accept exposure
keep the workaround
document the risk
agree monitoring
When leaders choose, they own.
That’s the point.
6) Do this Monday: the 60-minute Bypass Review Pack
Run this with your team, or with finance.
Step 1 (10 mins): Pick one process
P2P, O2C, expenses, R2R.
Step 2 (15 mins): Map “where money moves”
List the points where money is:
created
approved
changed
released
corrected

Where money moves infograph
Step 3 (15 mins): List the bypasses
Ask: “How would someone route around this on a busy day?”
Step 4 (15 mins): Choose one control move
Pick the smallest redesign that changes behaviour this week:
remove one handoff
lock a master data change to workflow
add reason codes
automate low risk, escalate exceptions
name one owner and one deputy
Step 5 (5 mins): Agree ownership and date
No shared inbox. No vague “we’ll look at it”.
7) A Concrete example: supplier bank detail change by email (and the control move that actually works)
Scenario:
A supplier “emails” to say they’ve changed banks and need future payments going to a new account.
It’s not unusual.
It’s also one of the easiest fraud routes there is.
What you see in practice:
The request comes to AP or procurement via email.
Someone updates the bank details in the ERP.
Payment goes out on the next run.
Evidence is a screenshot of the email chain.
The control often “exists” as a policy:
“Call the supplier back to confirm.”
But here’s the bypass:
the call-back is skipped when people are busy
or it’s done using the number in the email signature (which defeats the point)
or it’s done, but never logged anywhere
ownership is unclear, so nobody reviews the pattern
Why it happens:
Because the process is designed for speed, not independence.
And because the control is a manual step bolted on after the decision, not embedded at the decision point.
Exposure if repeated at scale:
One successful bank change can trigger repeated losses until someone notices.
And when it’s challenged, the business says: “But we followed the process. The email was there.”
That’s control theatre.
The “bad fix”:
Add another approval on bank changes.
This increases friction and pushes people to find a faster workaround.
The control move that works (design change):
Workflow-only bank changes: bank details can only be changed via a formal request workflow, not email.
Independent call-back: call-back must use a verified number from an independent source, contract, or supplier portal (not the email).
System logged evidence: the workflow requires a call-back tick-box plus notes (who, when, which number) before it can be submitted.
Dual control at the right point: one person changes, another person approves the change in-system before it becomes effective.
Pattern review: weekly report of all bank changes with exception flags (new bank + high value supplier, multiple changes, same requester).
What “good” looks like:
The evidence is created as a by-product of doing the work.
Not chased later.
Not “trust me, I called them”.
Soundbite for execs:
“This isn’t an AP control issue. It’s a money movement design issue. We’re letting bank details change without a clear, logged decision.”
8) Reusable template you can copy into your workpaper
Bypass Finding (decision format)
What we saw: Describe the bypass in plain words.
Why it happens: Pressure, unclear ownership, poor design, system gap.
Exposure: What can happen if repeated at scale (money, compliance, reputation).
Decision needed: Choose A or B.
Owner: Name one person.
By when: Date.
How we’ll know it worked: One measurable signal (override volume, bank changes logged, split invoices flagged).
That last line matters.
If you can’t measure it, you can’t manage drift.
Close
If your fraud work feels like chasing symptoms, switch your lens.
Audit the bypass.
Talk in decisions.
Redesign controls to change behaviour.
If you found this useful, please forward to a friend or colleague and tell them that I share practical tools like this every week in the Beyond the Lines™ newsletter, and ask them to subscribe below:
Subscribe here: https://beyondthelines.beehiiv.com/
Have a great week everyone, and thank you for subscribing.
Best,
Creator Beyond the Lines™
Free email without sacrificing your privacy
Gmail is free, but you pay with your data. Proton Mail is different.
We don’t scan your messages. We don’t sell your behavior. We don’t follow you across the internet.
Proton Mail gives you full-featured, private email without surveillance or creepy profiling. It’s email that respects your time, your attention, and your boundaries.
Email doesn’t have to cost your privacy.



