Everyone Has a Code of Conduct. Fewer Than Half Have the Control That Works Best.

ACFE's Occupational Fraud 2026 study measured eighteen anti-fraud controls at 2,402 victim organizations. The four that performed best are not the four that get bought.
Your organization almost certainly has a code of conduct. An external audit. An internal audit department. A hotline.
So did the victims.
The Association of Certified Fraud Examiners has just published Occupational Fraud 2026: A Report to the Nations, built from 2,402 cases of occupational fraud across 143 countries and territories, causing total losses of more than $3.4 billion. Among the organizations in that study — every one of which was defrauded — 88% had a code of conduct in place at the time. 83% had an external audit of their financial statements. 80% had an internal audit department. 73% had a hotline.
None of which means those controls do nothing. ACFE is clear that all eighteen controls it measured were associated with both lower losses and faster detection. It means something more specific, and more useful: the controls that are nearly universal are not the controls that moved the numbers most.
The four that moved the numbers
ACFE singles out four controls as associated with the largest reductions in both median loss and median duration: management review, proactive data monitoring and analysis, a code of conduct, and surprise audits.
Two of those four are close to universal. The code of conduct sits at 88% adoption, management review at 71%.
The other two are in place at fewer than half of victim organizations. Surprise audits, 44%. Proactive data monitoring and analysis, 49%.
And proactive data monitoring produced the second-largest loss reduction of all eighteen controls measured — behind only management review. Where it was present, the median loss was $70,000 against $150,000 where it was absent, and the median fraud ran nine months before detection instead of sixteen.
| Control | In place at | Median loss with | Median loss without | Reduction |
| Management review | 71% | $84,000 | $186,000 | 55% |
| Proactive data monitoring and analysis | 49% | $70,000 | $150,000 | 53% |
| Code of conduct | 88% | $100,000 | $200,000 | 50% |
| Surprise audits | 44% | $74,000 | $149,000 | 50% |
| Job rotation / mandatory vacation | 27% | $65,000 | $128,000 | 49% |
| Formal fraud risk assessments | 51% | $80,000 | $150,000 | 47% |
| Fraud training for managers/executives | 66% | $84,000 | $150,000 | 44% |
| Fraud training for employees | 67% | $85,000 | $141,000 | 40% |
| Employee support programs | 63% | $80,000 | $125,000 | 36% |
| External audit of financial statements | 83% | $100,000 | $150,000 | 33% |
| Internal audit department | 80% | $100,000 | $150,000 | 33% |
| Hotline | 73% | $100,000 | $150,000 | 33% |
| External audit of internal controls over financial reporting | 72% | $100,000 | $150,000 | 33% |
| Management certification of financial statements | 76% | $100,000 | $148,000 | 32% |
| Anti-fraud policy | 65% | $90,000 | $126,000 | 29% |
| Independent audit committee | 69% | $100,000 | $125,000 | 20% |
| Dedicated fraud department, function, or team | 54% | $100,000 | $125,000 | 20% |
| Rewards for whistleblowers | 14% | $100,000 | $108,000 | 7% |
Read that as association rather than proof of cause. Organizations that invest in one control tend to invest in others, and the report does not isolate the effect of any single one. But the shape of the table is hard to ignore: proactive data monitoring is also the only one of the eighteen that is a data control. Everything else on the list is an audit, a policy, a training program, a committee, or a reporting channel.
Why the gap matters: corruption is the constant
The case for closing that particular gap rests on what the most common fraud scheme actually is.
Across all fourteen industries with a usable sample in the study, corruption is the most frequent scheme in every single one — ranging from 34% of cases in education to 65% in agriculture. No other scheme is remotely that consistent. Corruption was present in 45% of all reported cases, at a median loss of $150,000.
Corruption is structurally different from the schemes a financial control is built to catch.
It requires at least two parties, and usually one of them sits outside the organization. It is negotiated before any transaction exists, which means the earliest artifact is a message, not a ledger entry. And it runs long — the study-wide median duration is 12 months.
A control that examines transactions finds the scheme once there is a transaction to find. By then you are most of a year in, and the ACFE duration data shows exactly what that costs: frauds caught within six months carry a median loss of $40,000; those running 25 to 36 months, $250,000.
The regional picture
The global averages understate the case in most of the markets we work in.
| Region | Cases | Median loss | Corruption |
| Southern Asia | 145 | $100,000 | 67% |
| Asia-Pacific | 143 | $150,000 | 61% |
| Middle East and North Africa | 143 | $123,000 | 59% |
| Eastern Europe and Western/Central Asia | 72 | $170,000 | 57% |
| Sub-Saharan Africa | 397 | $97,000 | 56% |
| Western Europe | 161 | $150,000 | 44% |
| United States and Canada | 876 | $110,000 | 33% |
Corruption appears in a third of North American cases and two-thirds of Southern Asian ones. Any fraud program designed around the global figure is calibrated for the wrong scheme mix in most of Asia, the Gulf, and Africa.
The recovery figures sharpen the point further. Between 47% and 66% of victim organizations in these regions recovered nothing at all — which makes spending on earlier detection a matter of loss avoidance rather than loss recovery.
What it looks like across ten industries
The scheme mix shifts by sector, but the ranking rarely does.
| Industry | Cases | Median loss | Corruption | Other leading schemes |
| Banking and financial services | 439 | $100,000 | 41% | Cash on hand 17%, noncash 17%, billing 13% |
| Government and public administration | 217 | $100,000 | 48% | Billing 19%, noncash 18%, payroll 15% |
| Manufacturing | 193 | $170,000 | 61% | Noncash 41%, billing 21%, expense reimbursements 15% |
| Health care | 140 | $100,000 | 44% | Billing 32%, noncash 17%, expense reimbursements 14% |
| Retail | 110 | $59,000 | 40% | Noncash 39%, skimming 20%, billing 19% |
| Construction | 93 | $120,000 | 50% | Billing 35%, noncash 23%, cash larceny 13% |
| Technology | 91 | $104,000 | 64% | Noncash 25%, billing 19%, expense reimbursements 15% |
| Energy | 89 | $220,000 | 58% | Noncash 29%, billing 20%, expense reimbursements 18% |
| Transportation and warehousing | 77 | $200,000 | 54% | Noncash 30%, billing 24%, expense reimbursements 12% |
| Insurance | 76 | $96,000 | 46% | Billing 20%, payroll 14%, check and payment tampering 13% |
Four patterns are worth drawing out.
Manufacturing, technology and energy run highest on corruption — 61%, 64% and 58%. In manufacturing, noncash assets sit at 41%, the highest figure of the ten; in this context “noncash” usually means drawings, bills of materials, process documentation and supplier pricing. The supplier relationship and the technical documentation move through the same channels, often the same email thread.
Construction is the billing exception. At 35%, it carries the highest billing figure here, with corruption right behind at 50%. Subcontractor invoicing, variation orders and quantity surveys are the mechanism, and shell-vendor arrangements are set up in correspondence weeks before the first invoice appears. The invoice is the last step, not the first.
Transportation and warehousing has almost no cash exposure. Cash larceny sits at 1% and cash on hand at 3% — the lowest in the study. Corruption is at 54% and noncash at 30%. Essentially everything that happens in this sector happens in documents and correspondence between brokers, agents and customs intermediaries.
Retail is the honest exception. It has the widest spread of scheme types and the lowest median loss at $59,000. Skimming at 20% and register disbursements at 11% are both the highest in the study, and both sit at the point of sale — which is a physical and transactional control problem, not a data security one. The head-office half of retail fraud, corruption at 40% and billing at 19%, is a different matter.
One further note on reading this table: ACFE states plainly that the distribution of cases by industry does not represent relative fraud risk. It reflects the cases submitted by the Certified Fraud Examiners who took part in the study. A high case count means a well-represented industry, not a dangerous one.
Correspondence is the control surface
If corruption is the constant, and corruption is negotiated rather than transacted, then the surface where it first becomes visible is communication.
That has three practical implications, and they are the same three in every sector.
Channel breadth. If an arrangement is negotiated on a messenger and the organization monitors only email, there is nothing to find. Coverage has to span mail protocols (SMTP, IMAP, POP3, MAPI), web traffic over HTTPS, messengers including WhatsApp, Telegram, Skype and Teams, and cloud storage including OneDrive, Office 365, Dropbox and Google Drive — alongside removable media and printing. In Zecurion's platform this is Traffic Control across more than 100 services and Device Control on the endpoint, with encryption applied to files written to removable media.
A retrievable archive. Tips remain the leading detection method at 43% of cases, nearly three times the next method, and more than half of tips come from employees. But a tip arrives at a median of twelve months in, and a tip is an allegation rather than evidence. The question that follows is always retrospective: what passed between these two people between March and September? Real-time alerting alone does not answer it. An archive that can be re-queried — and to which a newly written policy can be applied against historical data — does.
Relationship analysis. ACFE tracks twenty behavioral red flags, and 84% of perpetrators displayed at least one. Most of them are not data events: living beyond one's means, financial difficulties, irritability, family problems. Those belong to HR, line managers and the hotline. One is different. An unusually close association with a vendor or customer is a pattern in correspondence, and it is the single flag a data platform can honestly claim to observe. In corruption cases specifically it appears in 29% of cases, against 17% across all cases. Zecurion's behavioral analytics carries fifteen indicators, including contact with unknown external parties and a number of contacted people above the company average, and renders the result as a connection map — who has been corresponding with whom, over a chosen period. Where that produces something worth pursuing, the investigation module carries it as a case: tasks, statuses, owners, deadlines and attached evidence. Underneath all three sits the question of where regulated and commercially sensitive content actually lives. Discovery scans shared folders, SharePoint, Exchange and ODBC databases; files are identified by internal structure across more than 500 formats rather than by extension, including inside archives; and more than 30 predefined dictionaries cover common regulated content types. Where the question is who holds access rights rather than where the data sits, that is the DCAP product alongside DLP.
What we claim, and what we don't
Zecurion is a data security platform, implementing proactive data monitoring and analysis — one of the eighteen controls ACFE measured, and the one associated with the second-largest reduction in median loss. We also supply evidence to three others: the report library and incident record that a management review examines, the on-demand scanning that gives surprise audits a data-side equivalent, and the correspondence history that turns a hotline allegation into something an investigation can act on.
Three of the four controls that performed best on both measures. The fourth is a code of conduct, which is a policy instrument rather than a technical control — and which, at 88% adoption, you almost certainly already have.
The gap in most control sets is not the policy. It is the monitoring underneath it.
Source
Association of Certified Fraud Examiners, Occupational Fraud 2026: A Report to the Nations. Control adoption from Figure 27; loss and duration effects from Figures 28 and 29; industry case counts and median losses from Figure 25; industry scheme percentages from Figure 26, which covers only industries with 50 or more cases and whose percentages do not sum to 100 because one case can involve several schemes; behavioral red flags from Figure 55; regional data from Figures 74 to 115. The report is published for free download by the ACFE and is cited here as a third-party source.
Popular posts
One of the Largest Technical and Vocational Education and Training Service Providers in South Africa Uses Zecurion Next Generation DLP
One of the Largest World’s Upscale Hospitality Brands Protects Its Business in Turkey with Zecurion
Subscribe to our blog updates
You will receive only really useful emails and will always be able to unsubscribe from this mailing if, suddenly, your interests change