The most uncomfortable statistic in occupational fraud research is not the size of the loss. It is how the loss surfaces. The ACFE's 2024 *Occupational Fraud: A Report to the Nations* ranks the initial detection methods: tips 43%, internal audit 14%, management review 13%, document examination 6%, account reconciliation 5% — and by accident, also 5%. Reconciliation is the initial detection method at exactly the same rate as sheer accident.
For anyone who treats fraud detection and account reconciliation as one subject, that line is where the reading usually stops, with the conclusion that the control is not worth much. The correct reading is close to the opposite, and it needs three separations. Being the *first alarm* is not the same as being *effective*. The 5% share is not evidence that reconciliation is weak; in our reading of how it is actually practised, that share is better explained by how rarely and how shallowly reconciliation runs. And the same report is explicit about which kind of control does move the numbers.
One note on vintage: the 14th edition of the ACFE series was published in 2026. Every figure below comes from the 2024 edition.
"Detected first by" is a different question from "works"
The ACFE survey asks certified fraud examiners one question about each case: how was this fraud initially detected? The answer identifies who raised the first flag. It does not identify who resolved the case, quantified the damage, or assembled the evidence.
That distinction matters more than it looks. Tips lead at 43% because people see things — an unusual payment, a supplier nobody has met, a colleague who never takes leave. A hotline is a channel, not a control, and it is open every hour of every day. Reconciliation is a procedure, and procedures only speak when they run. Something that runs twelve times a year cannot compete on frequency with hundreds of employees watching continuously.
Second: the population here is discovered fraud. No survey can measure which controls the never-detected cases slipped past. So 5% does not mean "reconciliation stops only 5% of fraud." It means "in 5% of reported cases, reconciliation rang the first bell."
The claim "reconciliation solves fraud" does not follow from this data. What follows is narrower: reconciliation is a control that could ring the bell, and in most companies it has been muted.
What the same report says does move the numbers
The least quoted and most useful finding sits a few pages later: proactive data monitoring and analysis is among the controls associated with roughly halving both the median loss and the median duration. The reference points are known — a median loss of $145,000 and a median duration of 12 months.
Halving those two numbers is not the same as preventing fraud. It is more concrete than that: the same scheme becomes visible in six months instead of twelve, and the damage stops accumulating. Fraud economics are a function of time. Repeated payments, a fake vendor invoicing every month, a recurring adjustment — each additional month adds to the total. Any control that shortens duration shortens the amount.
The ACFE also reports that organizations lose an estimated 5% of revenue to fraud. Label that one correctly: it is an estimate drawn from a survey of certified fraud examiners, not a measurement. Read it as a sense of scale, not as a budget line.
The practical question, then, is not whether reconciliation belongs in a fraud programme. It is whether your reconciliation looks anything like proactive data monitoring — or like an annual exchange of letters.
Four reasons account reconciliation rarely rings first
It stops at the balance. The dominant practice in most purchase ledgers is the supplier statement: the vendor sends a statement of account, someone ticks it against the ledger, and it is signed off when the two closing figures agree. A balance agreement tells you the totals match. It does not tell you which item corresponds to which. When two opposite-signed errors cancel each other, the balance agrees and the reconciliation looks successful. Without line-level matching, statement reconciliation is correspondence, not detection.
It runs too late. The ACFE reports a median of 12 months before a fraud is detected. A reconciliation performed once a year, under close-cycle pressure, does not shorten those 12 months. It produces them.
Its scope is narrow. Statements are chased for accounts that carry a balance. Yet duplicate payments, overpayments and phantom-debt patterns tend to hide in accounts that have been netted to zero. An account that looks closed keeps looking closed because nobody examines it. We covered how those patterns are surfaced in our piece on financial anomaly detection.
The control is absent or overridden. The ACFE attributes 32% of cases to a lack of internal controls and 19% to override of existing controls. Override is the harder one: the procedure exists on paper, an owner is named, and the owner is the same person being controlled.
A scenario: the vendor that never carried a balance
Take a distribution business with a maintenance vendor set up years ago for a genuine one-off repair. The vendor record stays open. Every month a modest invoice arrives for callout work, approved by the manager who requested the original job — the same manager who asked for the vendor to be created.
Nothing about the account looks interesting. The invoice is well below the review threshold, so it never reaches a second approver. Payment goes out in the weekly batch, so the bank statement shows one aggregate line. The account nets to zero within the month, so it never appears on the list of balances to confirm, and no statement is ever requested from the vendor. At every level the finance function actually looks at — balance, threshold, exception report — this vendor is silent.
What would surface it is not a balance comparison; a balance comparison is exactly the test it passes. It surfaces when payment lines are matched against inbound e-invoice documents and something is missing on the document side, or when the amounts turn out to repeat to the cent month after month, or when a payment is pulled against an invoice that another payment already cleared. We described that last pattern in our article on phantom debt. None of these are clever tests. They are simply tests that operate on lines rather than on totals, and they run whether or not the account has a balance.
Where the losses land: median loss by sector
Median losses vary sharply by industry. In the 2024 edition, mining sits near the top with a median loss of $550,000; manufacturing is around $267,000.
What those sectors share is not coincidence: high-value supply chains, many subcontractor and service invoices, a time lag between site and head office, foreign-currency contracts. Many lines, high amounts, distant control points. It is also why supplier reconciliation in mining, energy and heavy manufacturing outgrows spreadsheets so quickly — the difference hides in one line among thousands, and a spreadsheet is a tool for looking at totals.
Four conditions for turning reconciliation into fraud detection
Line level. Match items, not balances. Every match should carry a written reason: the amount aligns, the date fits, the reference points to this invoice. A match without a stated reason cannot be audited, and an unauditable match is not a control.
Frequency. Monthly is the floor. For high-volume suppliers, a weekly run shortens the time it takes for a deviation to become visible to a matter of weeks — that is what you set against the ACFE's 12-month median, rather than any claim to have moved the median itself.
Scope. Include zero-balance, dormant and apparently closed accounts. That is where the patterns sit, and the standard balance-driven filter is precisely what keeps them out of view.
An independent third source. Comparing a ledger with a ledger is repetition, not control. Bank statements and e-invoice data are independent of the ledger, and that independence is where the control gets its strength.
History has priced that last point. In June 2020, the €1.9 billion supposedly held in escrow accounts at two Philippine banks in the Wirecard case turned out never to have existed — the confirmations were there, the money was not; we told that story in our Wirecard piece. In the Citibank–Revlon incident of August 2020, roughly $900 million of principal went out when $7.8 million of interest was intended — not fraud, but a control-design failure. And the loss that destroyed Barings in 1995 grew precisely because it sat in error account 88888, outside reconciliation, for years.
Evidencing that the control actually ran
Having a control and being able to evidence it are different things. In an audited company, "we reconcile" is not audit evidence on its own; what gets tested is who matched which item, when, against which independent source, and on what stated basis. A per-match reason and an approval trail are what turn a reconciliation into something an auditor can sample.
If you operate in Türkiye, there is a statutory threshold behind that: for 2026, the audit obligation for general ("other") companies is triggered when at least two of three criteria — TRY 500 million in total assets, TRY 1 billion in net sales, 150 employees — are exceeded in two consecutive reporting periods (Presidential Decree 11066, Official Gazette 17.03.2026 / 33199). We covered how a continuously audit-ready reconciliation is built in our piece on audit-ready reconciliation. Below the threshold, and in any other jurisdiction, the obligation changes but the evidence question does not.
Where iFinances sits in this picture
iFinances is not fraud detection software, and we would rather not have it presented that way. What it does is narrower and more concrete: it puts ledger/ERP records, bank statements and e-invoice data into one table; matches items with FIFO or invoice-specific clearing; splits partial payments and distributes lump-sum payments; absorbs rounding differences within tolerance; and uses the official CBRT rate for foreign-currency items. Every match carries a written reason. Missing invoices, duplicate records and off-pattern amounts are flagged — and the decision stays with a person.
iFinances does not keep your books, does not create entries, and never closes a line on its own. Even the fuzzy matching between bank narratives and company names is a suggestion; you approve it. You can invite the counterparty to upload their own statement through a secure link, with no software needed on their side. Data comes in independently of the ERP — Logo, SAP, Mikro, Netsis, Luca, Zirve or plain Excel.
Its contribution is one sentence: it turns reconciliation from an annual exchange of letters into a control that runs every month, at line level, with reasons attached. That is the direction the ACFE data points in — what shortens loss and duration is not the existence of a control but its frequency and depth. You can see how the supplier side is set up on our supplier statement reconciliation page.
Frequently Asked Questions
Does account reconciliation actually catch fraud?
In the ACFE's 2024 report, account reconciliation was the initial detection method in 5% of reported cases — the same share as "by accident." But the first method to raise a flag is not the same as the control that works. In most companies reconciliation runs once a year and only at balance level, which leaves it little chance to raise an alarm. The report places proactive data monitoring and analysis among the controls associated with roughly halving both the median loss and the median duration; we expect line-level monthly reconciliation to work in the same direction, but the ACFE does not measure it as a separate category. The data does not support "reconciliation solves fraud"; it supports "reconciliation stays silent because it is rarely run."
How is occupational fraud most often discovered?
The ACFE 2024 ranking of initial detection methods is: tips 43%, internal audit 14%, management review 13%, document examination 6%, account reconciliation 5%, by accident 5%. Tips lead by a wide margin because human channels are open continuously, while scheduled procedures speak only when they run. Hotlines and data-based controls are complements, not substitutes.
How long does fraud typically go undetected?
The 2024 report gives a median duration of 12 months and a median loss of $145,000. Duration and amount are linked: the longer a scheme runs, the more repeated payments accumulate. The report places proactive data monitoring and analysis among the controls associated with roughly halving both figures. Note that the ACFE's 14th edition appeared in 2026; these figures are from the 2024 edition.
Which accounts should be in scope if fraud detection is the goal?
Not only the ones carrying a balance. Supplier statement chasing is normally driven off open balances, which is exactly the wrong filter here: duplicate payments, overpayments and low-value recurring schemes tend to sit in accounts that net to zero every month and therefore never appear on the follow-up list. A scope rule that includes dormant, zero-balance and recently closed accounts costs little and changes what the control can see.
Is a reconciliation good enough as audit evidence?
A signed statement agreeing two closing balances shows that someone corresponded with the vendor. What an auditor tests is narrower: who matched which item, when, against which independent source, and on what stated basis. Reconciliations that keep a per-match reason and an approval trail survive that test; a ticked statement usually does not.
✦ iFinances — See what you're missing.



