How to protect your business against internal and external fraud
Fraud has long been a challenge for businesses and public sector organizations. In 2019, we wrote about the most common types of fraud , and even then it was clear that the number of cases was increasing and that in many cases they were becoming more sophisticated. It has probably not escaped anyone's attention that technological developments since 2019 have been rapid, and we are now in a situation where certain types of fraud are almost impossible to detect through common sense and vigilance alone—established processes and system support are now also required to have a realistic chance of protecting oneself effectively.
In an article from 2018 , we wrote about CEO fraud where a fraudster typically pretends to be a senior executive at the company and requests an urgent payment over the phone or by email. Similar scams are still being carried out today, but with the difference that fraudsters can now use various AI applications. There are now many examples of cases where fraudsters have used fake voices and, in some cases, even credible AI avatars, known as deepfakes, to stage video meetings that never actually took place. CNN reported as early as 2024 about such a case in Hong Kong, where a global company was tricked into paying out $25 million after an employee believed they had had a video meeting with the company's management. Although this type of advanced fraud is fortunately not very common today, it is easy to see a trend where it will become commonplace as technology improves and becomes even more accessible.
“It is worrying that virtually all forms of fraud have increased in recent years. The trend is widespread, rapid, and affects companies in all industries. The methods are also becoming increasingly sophisticated—it is not uncommon for even very vigilant entrepreneurs to fall victim.”
– Entrepreneurs (Crimes against entrepreneurs, 2025)
CEO fraud is just one method criminals use to try to deceive organizations, and there are other forms of fraud that are more common. Below, we list frauds that are common in Sweden today and suggest activities and processes that can be implemented in your business to protect yourself.
Internal fraud
Although it is sad to admit, the majority of fraud against companies is linked to someone within the organization. Reports from KPMG and PWC, among others, show that the majority of fraud cases can be linked to one or more individuals within the organization. This may involve employees acting alone, but it is also common for one or more individuals within the organization to act in collusion with one or more external parties.
Embezzlement
Embezzlement is a crime whereby a person who has been entrusted with money or property in a position of trust unlawfully appropriates these or uses them for their own gain. This is a common crime within organizations, usually involving an employee responsible for payments transferring money to themselves in various ways, either directly or via companies and partners. This may involve changing the account at the time of payment so that a payment is redirected to themselves or a company they control. It may also involve the employee, alone or together with others, falsifying invoices and making incorrect payments to companies that have been added to the company's supplier register. The latter example is a type of fraud that is more difficult to detect and can go on for a long time.
Corruption
Where embezzlement involves using one's authority for fraud, corruption offences instead involve using one's position and power. An example could be a high-ranking person in an organisation who chooses to bring in a supplier with whom they have an undisclosed connection, thereby benefiting themselves in an improper manner.
What measures can be taken to protect oneself?
There are several things an organization can do to reduce the risk of internal fraud. An important part is to demonstrate internally that you have a clear process and follow-up linked to payments. In many cases, it is a matter of "opportunity makes the thief," and by having clear internal processes, you can curb the temptation to embezzle money.
Certificate flow and logging when setting up new suppliers
Use a system support that ensures that two people are involved in approving new suppliers. Also ensure that the process is logged so that there is a history of the supplier arrangement, the checks that have been carried out, and the internal communication that has taken place in connection with this.
Warnings for unapproved suppliers and deviating accounts/amounts
In cases where payments are made to suppliers and/or accounts that are not listed in the supplier register, it is important to have an internal warning system in place. A good system should also detect if, for example, account details have been changed for an already approved supplier or if an amount being paid out is unusual compared to historical payments.
Perform ongoing secondary checks
Ensure that employees do not have unknown connections to suppliers. Most businesses have a policy that requires employees to report secondary employment and other commitments. Make sure to carry out checks, either on an ongoing basis or at selected times, to ensure that your employees do not have secondary employment that has not been approved. This reduces the risk of, for example, a senior employee improperly favoring a company in which they have undisclosed interests.
The primary driver of the opportunity to commit fraud is a lack of internal controls. In fact, approximately 93% of cases can be attributed to this root cause.
– KPMG Sweden (The profile of fraudsters and the changing nature of fraud, 2025)
External fraud
External fraud is common, and there are many approaches. Below are two common methods that have also increased in recent years.
Invoice fraud
Invoice fraud usually consists of false or misleading invoices sent with the aim of getting businesses to pay incorrectly for goods or services that they have not ordered. Recent data from Företagarna shows that 60% of companies that have been victims of some form of fraud say they have been victims of invoice fraud. This is an increase from 43% in 2023.
CEO fraud
CEO fraud involves an external party posing as a senior manager (e.g., CEO) to trick employees into making unauthorized payments. Here too, data from Företagarna shows an increase. In their latest report, 10% of those who had been victims of some form of fraud said they had been victims of CEO fraud. This was an increase from 6% in 2023.
What measures can be taken to protect oneself?
There are several things an organization can do to reduce the risk of external fraud. One important aspect is training your own staff on what methods to look out for. Another is to ensure that staff feel confident in following established processes. One example is to never pay money to companies suspected of being fraudulent or to make an urgent payment to a new account without first ensuring internally, via predetermined channels, that it is indeed correct.
Catch scam companies – before they end up on scam lists
A common recommendation when onboarding new suppliers is to ensure that the company is not listed on Svenska Handel’s warning list. With Betalkontroll, this check is performed automatically, and we’ve gone a step further. We’ve observed that scam companies often manage to commit numerous frauds before they actually end up on scam lists. We’ve also seen that criminals often switch to new companies once they’re caught. That’s why we’ve created an indicator that flags companies associated with listed scam companies. This allows you to receive a warning about suspected scam companies even before they appear on official lists.
Catch the fraudsters hiding behind factoring companies
A common tactic used by fraudulent companies is to utilize factoring companies. This makes it more difficult for organizations to conduct proper due diligence on the operating company. At Betalkontroll, we can address this by ensuring that the necessary checks are performed on the operating company and not just on the factoring company. This is a crucial step in ensuring that checks are conducted on the actual counterparty.
Catch unscrupulous operators with whom you should not do business
The Swedish National Council for Crime Prevention estimates that nearly 2% of companies have ties to criminal networks. Based on checks conducted against the Swedish legal database through our partner Kapitel 13, approximately 3% of companies—or one of their executives—have criminal convictions that justify their exclusion from public procurement. An important part of protecting your business against external fraud is therefore ensuring that you do not do business with these companies. At Betalkontroll, we offer an integrated solution for checking against the Swedish legal database—a solid safeguard against doing business with unscrupulous, or outright criminal, actors.
Warnings for unapproved suppliers and deviating accounts/amounts
This is also an important control for external fraud. By catching payments made to suppliers and/or accounts that are not listed in the supplier register, the risk of fake invoices slipping through unnoticed is reduced. Fake invoices often involve relatively small amounts, but overall they represent a significant cost for organizations.
Summary
Fraud targeting businesses and public sector organizations has always existed, but unfortunately, it is a growing problem. New technology enables increasingly sophisticated methods and allows fraudsters to target a large number of victims simultaneously. This places greater demands on organizations to have internal processes in place to address this threat. Part of this involves training employees, and another part involves having processes in place that ensure actions are taken to make it harder for fraudsters to succeed. Tools like Betalkontroll cannot prevent all fraud, but they ensure that internal processes are in place for handling payments and suppliers in a secure and efficient manner.