Financial Strategy

When the person you trust the most is the biggest risk in your business 

Five real cases of finance managers abusing their position – and what every small business owner needs to know before it happens to them. 

When the person you trust the most is the biggest risk in your business 

A NOTE FROM EXPERIENCE 

Early in an auditing career, there is a lesson that stays with you. During a risk assessment, your supervisor points to the finance manager – loyal, long-serving, never takes a day off, handles everything personally, respected and trusted by the whole team. “That,” your supervisor says, “is your biggest red flag.” 

It feels counterintuitive, they are your fellow professionals and a significant element of the client’s business success. But the logic is cold and clear: someone who is rarely absent, refuses to delegate, and guards every financial process, is someone who cannot afford to let anyone else look. The fraud examiner’s world calls it the indispensable employee. The evidence is damning and the risk is very real. 

FIVE CASES – ALL ON THE PUBLIC RECORD 

Case 01  The finance manager who became irreplaceable – then stole £1.4m 

SDE Group, Chesterfield · UK · 2024 

  £1.4 million       11 years       United Kingdom   

Deborah Thorlby-Hall joined as an accounts assistant and gradually absorbed every financial process. When the finance director left, she stepped into the role – attending board meetings, managing all supplier relationships, controlling every payment. Nobody else knew the system well enough to question her. 

She created false invoices to disguise transfers and siphoned funds for over a decade. The money funded a Harley Davidson, a Range Rover, and over £87,000 at a single clothing retailer. She was sentenced to six years in prison in October 2024. 

RED FLAG  Her control escalated every time a layer of oversight was removed. The departure of the finance director was the moment the last check disappeared – and the fraud accelerated. 

Case 02  The sole bookkeeper who closed a 32-year-old business 

Concept Display Systems, West Midlands · UK · 2023 

  £678,636       4 years       United Kingdom   

For four years, one bookkeeper was the only financial employee at a 32-year-old manufacturer. She created fictitious suppliers, opened accounts in their names, and transferred £678,636 before routing it to herself. The business never recovered and was forced to close. 

The fraud was not discovered internally. It only came to light when HMRC and HSBC independently raised concerns about unpaid obligations. 

RED FLAG  A sole bookkeeper with no oversight is not an efficiency measure – it is an open door. This business did not lose money to a sophisticated fraudster. It lost money because there was nobody else in the room. 

Case 03  The trusted bookkeeper discovered only when she went on holiday 

Superior Fence, United States 

  $1.4 million       Multiple years       United States   

The bookkeeper managed payroll, paid all bills, reconciled the books, and held access to every account. Her scheme redirected vendor payments to herself. Because she controlled everything, no process would naturally surface the transfers. 

The fraud was uncovered entirely by accident – when she went on holiday, vendors called to complain their invoices had not been paid. For the first time, someone else had to look at the accounts. 

RED FLAG  The holiday was the accidental audit the business had never conducted deliberately. Fraud examiners note this pattern constantly – the moment a fraudster is absent, the scheme becomes visible within days. 

Case 04  The office manager who threw a £39,000 Halloween party with stolen funds 

McLean Properties, Edinburgh · Scotland · 2024 

  £900,000+       3 years       Scotland   

Emma Hunt processed rental payments, managed tenant deposits, and handled supplier invoices for an Edinburgh property firm – with minimal supervision. Over three years she diverted rental income, fabricated deposits, and created false invoices, spending the proceeds on a five-star Caribbean holiday, designer goods, and a single Halloween party for 80 friends costing £39,000. 

She was convicted of fraud, embezzlement, and money laundering, and sentenced to three years in prison. 

RED FLAG  Living visibly beyond one’s means – particularly when combined with sole control of finances – is one of the most consistent behavioural signals that something is wrong. It appears in the ACFE’s global fraud data across thousands of cases. 

Case 05  The bookkeeper who ran a $9.8m scheme for six uninterrupted years 

Broward County, Florida · United States · 2025 

  $9.8 million       6 years       United States   

Hava Yfrah Austin held signature authority over her employer’s bank accounts while simultaneously running her own bookkeeping practice. Between 2018 and 2024 she executed hundreds of unauthorised wire transfers, spending much of the proceeds at local casinos. No independent review ever took place. 

The scheme ran for six years – more than five times the median fraud duration identified by the ACFE. She was sentenced to 51 months in federal prison in 2025. 

RED FLAG  Signature authority over bank accounts should never rest with a single individual – internal or external – without independent checks. Absence of review is not trust. It is opportunity. 

Five quick governance checks 

None of these cases required sophisticated fraud prevention. They required basic financial structure.  The people convicted in the cases presented above may not have been “bad people”, they may have been victims of circumstance, but when opportunity meets desperation or mental instability, money is a cruel mistress. 

Regardless of the size, maturity or complexity of your business there are some simple checks and processes you can implement to reduce the risk of your most trusted professional becoming your weakest link. 

✓  Split duties – no single person owns the full cycle 

The person recording transactions should not also reconcile the bank, approve payments, or control account access. 

✓  Mandate holidays and use them as informal audits 

Require at least one continuous week off per year for anyone with financial access – and ensure someone else covers their duties during that time. 

✓  Review bank statements yourself, every month 

As the owner, personally review statements and spot-check a sample of payments. Fraudsters rely on the assumption that the owner does not look. 

✓  Commission an independent annual review 

Engage an external accountant with direct access to your bank statements – not just records supplied by your bookkeeper. The independence is the point. 

✓  Never cede complete access – it is your business 

You should always hold your own login to your bank accounts, accounting software, and payroll system. If only your bookkeeper can see the books, you have already lost the most important control you have. 

Don’t wait for something to go wrong. 

We work with small businesses to design robust financial control environments – practical, proportionate, and built around simple supervisory fire breaks that work even with small teams. 

Using tools like ApprovalMax, Apron, and Hubdoc, alongside your current accounting software, we can build a transparent, documented approval layer into your existing workflow – so that no single person can ever control, approve, and conceal a transaction without another set of eyes. 

Get in touch to find out how we can help protect your business. 

Share
Tweet
Email

Take the first step towards your business' financial transformation.

Ready to simplify your financial processes, boost growth, and make your mark? Connect with us and discover the power of strategic financial guidance.