Who this article applies to: CFOs, controllers, and internal audit professionals at financial institutions
Occupational fraud remains a persistent and costly risk for financial services organizations. In its 2026 Report to the Nations, the Association of Certified Fraud Examiners studied 2,402 fraud cases globally totaling more than $3.4 billion in losses across industries, including financial services. The report estimates that organizations lose about 5% of annual revenue to fraud, underscoring that no institution is immune. Equally important, many organizations never fully recover those losses, with over half of victims recovering nothing, highlighting the need for a proactive fraud risk management approach rather than post-event remediation.
Risk profile for banks and investment firms
The report includes targeted insights for the banking and financial services sector:
- Median loss per case: $100,000
- Average loss per case: $1,535,000
- Median duration: 8 months
These figures are consistent with overall global trends, but the financial sector’s exposure to high-value transactions, complex systems, and regulatory scrutiny increases both the potential impact and reputational risk associated with fraud events.
Fraud types most relevant to financial institutions
The report identifies three primary fraud categories:
- Asset misappropriation: 90% of cases; lower median loss
- Corruption: 45% of cases—includes conflicts of interest and kickbacks; moderate loss
- Financial statement fraud: 6% of cases; highest losses at $1 million median
Within financial services, asset misappropriation-related schemes are most prevalent. However, although financial statement fraud is less frequent, it presents the greatest dollar exposure.
Fraud detection and why whistleblower programs matter
Because fraud losses escalate over time, improving detection is one of the most effective ways to limit impact. Key insights include:
- 43% of fraud cases were detected through tips, over half of which came from employees.
- Email and web-based reporting channels are now more commonly used than hotlines.
Institutions with strong whistleblower frameworks and accessible reporting channels are significantly better positioned to detect fraud early and minimize losses. The most effective frameworks are comprehensive, independent, and trusted by employees.
Higher roles, higher fraud exposure
Fraud risk is closely tied to access and authority, requiring strong governance and oversight. Employees and managers commit most fraud, but executives cause the largest losses, with risk increasing alongside authority, tenure, and collusion.
Behavioral red flags
Most perpetrators exhibit warning signs, such as financial pressure or unusual relationships. Behavioral monitoring can enhance fraud detection, particularly for high-risk roles. Always consider the components of the fraud triangle: incentive, opportunity, and rationalization.
Internal control failure
Approximately 70% of fraud cases involve control failures rather than absence of controls. For regulated institutions, this highlights the need for effective execution and monitoring of controls, not just design.
Core controls include management review, data monitoring, and surprise audits. Fraud awareness training and regular reassessment of risk frameworks are also essential, as many organizations still respond to fraud reactively rather than proactively.
Aligning fraud risk management with strategic decision-making
Fraud risk extends beyond operations to compliance, governance, and reputation. Organizations that emphasize active monitoring, strong controls, and a culture of accountability are best positioned to reduce losses and strengthen risk management. In our complimentary whitepaper on preventing financial institution fraud, we take a deeper look at how to successfully implement a strong anti-fraud plan. Commit to enhancing fraud prevention to build trust with your board, employees, customers, and the broader public—an investment that delivers strong value for any financial institution.
Key takeaways
- Recognize persistent fraud risk, with organizations losing an estimated 5% of annual revenue to fraud and many recovering none of those losses.
- Improve detection by strengthening whistleblower programs and digital reporting channels, especially for employees.
- Address high-impact fraud by focusing on asset misappropriation while monitoring high-cost financial statement fraud.
- Increase oversight of senior roles, where fraud risk and losses are greater.
- Check internal controls with monitoring, management review, and ongoing risk assessment.
BerryDunn can help
Our risk management team helps clients develop and implement effective risk management programs tailored to each organization’s size, risk level, and resources. Learn more about our team and services.