Vonya Global

Vonya Global Vonya Global is a multinational consulting firm that partners with business leaders on a range of assurance and consulting services.

This week's fraud headline comes from the Wall Street Journal. It's another reminder that strong governance and effectiv...
09/02/2026

This week's fraud headline comes from the Wall Street Journal. It's another reminder that strong governance and effective oversight matter.

The founder of First Liberty Building & Loan recently pleaded guilty to wire fraud in connection with a $140 million Ponzi scheme that allegedly defrauded approximately 300 investors. Investors were promised attractive returns from short-term business lending activities, but investor funds were instead used to make Ponzi-style payments to existing investors and finance personal expenditures.

While every fraud scheme has unique characteristics, the underlying control failures are often remarkably similar.

• Excessive concentration of authority in a founder-led organization
• Insufficient independent oversight of investment activities and lending decisions
• Lack of transparency regarding the actual use of investor funds
• Weak monitoring of related-party transactions and conflicts of interest
• Inadequate verification that reported returns were supported by legitimate operating performance
• A culture where trust in leadership appeared to outweigh healthy skepticism and challenge

As auditors and risk professionals know, fraud rarely occurs because controls fail in a single area. It is usually the result of multiple governance, oversight, and monitoring breakdowns occurring simultaneously.

What Boards and Audit Committees Should Be Asking:
✔ How do we independently verify management's representations regarding financial performance and cash flows?
✔ What controls exist to detect management override of established processes?
✔ Are related-party transactions identified, reviewed, and approved through an independent process?
✔ Is there adequate segregation of duties around the movement and reporting of funds?
✔ Do we have effective whistleblower mechanisms that allow concerns to bypass management?
✔ Are internal audit, compliance, and risk management functions empowered to challenge senior leadership?
✔ What fraud risk indicators are being monitored and reported to the Board on a regular basis?

One of the most important lessons from cases like this is that strong financial results and a charismatic leadership team should never reduce the rigor of oversight. Effective governance is designed for the times when trust is misplaced.

Candidates face calls to return funds

A former Williams-Sonoma executive recently pleaded guilty to participating in a $16 million kickback and commission div...
08/29/2026

A former Williams-Sonoma executive recently pleaded guilty to participating in a $16 million kickback and commission diversion scheme involving warehouse equipment purchases, logistics services, and real estate transactions. The executive used a shell company to receive kickbacks from vendors and diverted brokerage commissions that should have been paid to legitimate third parties.

It is another unfortunate case of internal control and governance failures.

Here are some risk indicators worth noting:
1️⃣Excessive authority concentrated in a single executive responsible for vendor selection, contracting, and project oversight
2️⃣Inadequate conflict-of-interest disclosures and monitoring
3️⃣Weak due diligence over third parties and vendor ownership relationships
4️⃣Insufficient review of large procurement and real estate transactions
5️⃣Lack of analytics designed to identify unusual vendor payments and commission arrangements (which is much easier these days with AI)
6️⃣Limited independent oversight of strategic sourcing and capital project expenditures

For Boards and Audit Committees, this case serves as a reminder that fraud risk extends well beyond finance and accounting functions. Procurement, supply chain, facilities management, real estate, and vendor management activities often involve significant spending and can create opportunities for kickbacks, self-dealing, and undisclosed conflicts of interest.

Strong governance requires periodic conflict-of-interest certifications, robust third-party due diligence, data analytics focused on vendor risk, and independent reviews of high-dollar sourcing and contracting decisions. Internal audit should also periodically evaluate procurement and vendor management controls.

Fraud schemes of this nature rarely succeed because controls do not exist. More often, they succeed because oversight fails to challenge trusted individuals with significant authority.

❓❓❓What do you believe is the most effective control for preventing executive-level kickback schemes: vendor due diligence, conflict-of-interest monitoring, data analytics, or independent procurement reviews?

VP will be sentenced in federal court

Come join me on September 16 for a 3-hour cruise on Lake Michigan.The IIA Chicago Chapter's Career Advisory Committee wa...
08/26/2026

Come join me on September 16 for a 3-hour cruise on Lake Michigan.

The IIA Chicago Chapter's Career Advisory Committee warmly invites you aboard the Island Party Boat’s Enchantment for an unforgettable evening of professional connection, food, drinks, and skyline views — all while earning 1 hour of CPE!

Join the IIA Chicago Chapter on the lake

A former finance director was recently sentenced to 6.5 years in prison after embezzling more than $10 million from his ...
08/21/2026

A former finance director was recently sentenced to 6.5 years in prison after embezzling more than $10 million from his employer over a 16-year period. According to prosecutors, he concealed the fraud by altering bank statements, paying personal expenses with company funds, awarding himself unauthorized bonuses, and directing company funds to personal accounts.

While the dollar amount is shocking, the more important question for Boards and Audit Committees is: How did this go undetected for so long?

Almost every case I post on Facebook reveal common control breakdowns:
• Inadequate segregation of duties within the finance function
• Lack of independent review of bank reconciliations and cash disbursements
• Overreliance on trust in a long-tenured employee (Trust is important but it is not an internal control)
• Insufficient monitoring of executive compensation and bonus payments
• Failure to obtain bank information directly from financial institutions
• Weak internal audit coverage of treasury, cash management, and disbursement processes

Boards and Audit Committees should view this case as a reminder that prevention is not simply a management responsibility. Effective oversight requires periodic reviews of fraud risk assessments, independent validation of key financial controls, direct engagement with internal and external auditors, and ongoing scrutiny of areas where a single individual has the ability to both execute and conceal transactions.

Fraud schemes rarely begin as $10 million thefts. They often start with a small control failure that goes unnoticed. This case started small and built steam over 16 years. Strong governance, independent oversight, and a healthy degree of professional skepticism remain some of the most effective defenses against financial misconduct.

Former finance director pleads guilty

Internal Controls help organizations reduce risk, improve financial reporting, strengthen compliance, ensure critical pr...
08/17/2026

Internal Controls help organizations reduce risk, improve financial reporting, strengthen compliance, ensure critical processes operate consistently, deter fraud, and create accountability across operations.

Jesse Laseman wrote this article, co-authored by Tim Lietz and me. Give it a read and let me know what you think.

Enhance compliance & deter fraud

Join Jesse Laseman and me for this free webinar on August 19. This session qualifies for YellowBook CPE credit.Designing...
08/14/2026

Join Jesse Laseman and me for this free webinar on August 19. This session qualifies for YellowBook CPE credit.

Designing and documenting effective internal controls
Effective internal controls are more than a compliance exercise, they are essential to accountability, operational effectiveness, stewardship of public resources, and maintaining public trust. In this session, we will explore what strong internal controls look like in practice and discuss common control design and documentation challenges organizations face today.

Using real-world examples and observations from internal control assessments, attendees will learn how to design controls that address risk, distinguish between routine activities and true controls, and create documentation that stands up to scrutiny. We will also discuss common obstacles organizations encounter, including staffing shortages, turnover, and evolving processes, and how these challenges impact control effectiveness.
The session will conclude with practical guidance on preparing for an internal control assessment and strengthening an organization’s overall control environment.

Join me and Jesse Laseman for YB CPE

🚨 When the CFO Is the Fraudster: A $3 Million Internal Control FailureA former CFO of a Miami-based hedge fund recently ...
08/12/2026

🚨 When the CFO Is the Fraudster: A $3 Million Internal Control Failure

A former CFO of a Miami-based hedge fund recently pleaded guilty to a years-long scheme that allegedly embezzled more than $3 million from his employer. According to the Department of Justice, the CFO used fictitious consulting companies under his control, submitted fraudulent invoices for services never performed, authorized unauthorized payments, and charged personal expenses to company credit cards. He also allegedly misled the organization's external auditor to conceal the scheme.

This case is a powerful reminder that fraud risks do not disappear simply because an organization has experienced finance professionals, external audits, or established processes. In many cases, the greatest risk comes from management override of controls.

What internal control failures may have allowed this to happen?

✅ Insufficient independent review and approval of vendor payments

✅ Weak vendor onboarding and beneficial ownership verification procedures

✅ Excessive authority concentrated in a single executive

✅ Lack of segregation of duties within the finance function

✅ Inadequate monitoring of corporate credit card activity

✅ Failure to identify related-party transactions and conflicts of interest

✅ Insufficient scrutiny of unusual payments and consulting arrangements

✅ Inability to detect management override and misleading information provided to auditors

This fraud reportedly continued for years, highlighting the importance of ongoing monitoring and independent challenge of executive actions.

What should Boards and Audit Committees do?

🔹 Challenge management on how the organization identifies and mitigates management override risks.

🔹 Require periodic reviews of vendor master files, related-party transactions, and beneficial ownership information.

🔹 Ensure high-risk payments, consulting arrangements, and executive expenses receive independent oversight and review.

🔹 Leverage data analytics to identify unusual payment patterns, duplicate vendors, and transaction anomalies.

🔹 Confirm segregation-of-duties conflicts are identified and appropriately mitigated.

🔹 Meet regularly with internal and external auditors to discuss fraud risks, control weaknesses, and concerns involving executive management.

🔹 Encourage a strong speak-up culture and whistleblower program that allows concerns to be raised without fear of retaliation.

The most important lesson from this case is that controls designed to prevent employee fraud are often ineffective when the individual committing the fraud is the person responsible for approving, overseeing, or monitoring those same controls. Strong governance, independent oversight, and a healthy level of skepticism remain some of the most effective defenses against executive misconduct.

The former CFO used fake invoices

🚨Fraud Risks Are Not Limited to Finance DepartmentsA former Senior Systems Administrator at a North Carolina hospice org...
08/04/2026

🚨Fraud Risks Are Not Limited to Finance Departments

A former Senior Systems Administrator at a North Carolina hospice organization was recently convicted for embezzling nearly $1 million over a three-year period. The employee used a company credit card, created fraudulent invoices, routed payments, and used created a fictitious company to conceal the ultimate beneficiary of the payments.

What internal control failures may have allowed this to happen?

✅ Inadequate review and approval of vendor invoices

✅ Weak controls over corporate credit card transactions

✅ Failure to verify vendor legitimacy and ownership

✅ Insufficient segregation of duties between purchasing, payment processing, and invoice approval

✅ Lack of monitoring over employee-controlled payment accounts

✅ Ineffective analytics to identify unusual spending patterns and duplicate or suspicious vendors

✅ Delayed detection despite the scheme occurring over multiple years

This case highlights a common fraud scenario: an employee with specialized knowledge of systems and processes exploits gaps in oversight and vendor payment controls. These risks are easily prevented.

What should Boards and Audit Committees do?

🔹 Require management to periodically assess fraud risks associated with procurement, accounts payable, credit cards, and vendor management processes.

🔹 Ensure independent reviews of new vendors, including validation of ownership, tax information, addresses, and banking details.

🔹 Request periodic data analytics over vendor payments, employee reimbursements, and purchasing card transactions to identify anomalies.

🔹 Confirm that segregation-of-duties conflicts are identified, monitored, and mitigated, particularly for employees with elevated system access.

🔹 Require internal audit to periodically test vendor master file changes, invoice approvals, and payment controls.

🔹 Establish reporting on fraud indicators and control exceptions, not just financial performance metrics.

🔹 Promote a strong ethical culture and whistleblower program that enables concerns to be reported and investigated promptly.

Fraud schemes involving fictitious vendors and unauthorized payments continue to occur because organizations often trust long-tenured employees and fail to independently verify transactions. Effective governance requires challenging assumptions, monitoring high-risk activities, and ensuring key controls remain effective as business processes evolve.

Claimed to be making IT purchases

This is unexpected career advice from an unexpected source. Joe Rogan recently interviewed Mr. Beast on the JRE Podcast....
07/31/2026

This is unexpected career advice from an unexpected source. Joe Rogan recently interviewed Mr. Beast on the JRE Podcast. Maybe you listened already? During the interview there were snippets of great career advice. This clip is one of them: "You can't be your own boss and also be a "terrible" employee."

During the interview there were snippets of great career advice. This clip is one of them: "You can't be your own boss and also be a "terrible" employee."

It is worth listening to and reflecting on your role as an employee, whether self-employed or not.

Unexpected career advice from MrBeast

🚨 Internal Control Failures Can Be Costly: Alleged $5M+ Embezzlement at Cash Handling VendorFederal prosecutors recently...
07/29/2026

🚨 Internal Control Failures Can Be Costly: Alleged $5M+ Embezzlement at Cash Handling Vendor
Federal prosecutors recently charged two executives of a New Jersey security and cash-handling company with allegedly embezzling more than $5 million from cash held on behalf of a bank. According to the indictment, the executives allegedly removed cash from company vaults over several years and used the funds for personal purchases, business expenses, vehicles, home improvements, and other expenditures.

What control failures may have contributed to this?
✅ Inadequate segregation of duties over high-risk cash handling activities
✅ Insufficient independent reconciliations and verification of vault balances
✅ Lack of effective monitoring of executive access and transactions
✅ Weak governance over third-party cash custodians
✅ Failure to detect or prevent management override of controls
✅ Limited independent oversight of a high-risk, cash-intensive process

One of the most important lessons from this case is that fraud often occurs not because controls do not exist, but because individuals with authority can override them.

What should Boards and Audit Committees do?
🔹 Ensure management has implemented strong controls over cash, assets, and other high-risk processes.
🔹 Require periodic independent audits, surprise reviews, and reconciliations of critical assets.
🔹 Focus on risks associated with management override, especially where a small group of executives controls key processes.
🔹 Strengthen third-party risk management and demand independent assurance over outsourced services.
🔹 Review fraud risk assessments regularly and challenge management on how key controls are monitored.
🔹 Encourage a culture of accountability, transparency, and reporting of concerns without fear of retaliation.

This case serves as a reminder that effective governance is not just about having controls on paper—it's about ensuring those controls are independently monitored, regularly challenged, and capable of detecting misconduct at every level of the organization.

Management overrides of controls

Address

150 N Michigan Avenue
Chicago, IL
60601

Alerts

Be the first to know and let us send you an email when Vonya Global posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share