
Internal fraud accounts for 5% of revenue lost worldwide
On the integrity of people and insider threats
When organisations think about internal fraud, they tend to picture an opportunist somewhere lower down: someone siphoning off small amounts who is caught sooner or later. The figures tell a different story. The greatest damage comes from the top. The highest loss per case is caused by owners and executives, with a median of USD 500,000, and the higher the position, the greater the damage.¹ This is the experienced hand with budget authority, influence over suppliers and a long track record — precisely the person who is rarely checked, because the trust is already there.
The greatest risk does not come from the employee you distrust, but from the one you trust most. Worldwide, organisations lose an estimated 5% of their revenue each year to internal fraud, at an average loss of USD 1.7 million per case.² It is rarely the large numbers that cost the most, but the few who draw the least attention.

From peripheral issue to structural vulnerability
In the space of a few years, insider risk has moved from a peripheral issue to a structural vulnerability. Recent research among European organisations shows that 76% experienced an internal incident over the past year, up from 66% in 2019.³ Resilience has not kept pace: only 30% of organisations at elevated risk have an insider threat programme (partly) in place, and 84% do not feel properly equipped to recognise and handle such incidents.⁴
Why does the problem prove so persistent? Because it is structural. In more than half of all fraud cases, internal controls are absent or existing controls are deliberately overridden by management.⁵ The insider knows which exceptions to the rule exist and which controls exist only on paper, and uses position and reputation to deflect critical questions or stop them before they are asked. Collusion with a colleague or a supplier increases the damage further. A fraudster can make transactions look legitimate simply by drawing on the trust of colleagues. No security needs to be breached.

The risk: long-serving staff and senior managers
For Dutch organisations in regulated sectors — financial services, energy, telecoms and defence — this is a real risk. These are precisely the environments where roles with significant autonomy, payment authority and access to sensitive information are concentrated. And it is precisely among long-serving staff and senior managers that segregation of duties and repeat screening are most often missing, because the position itself is treated as a safeguard. Many organisations focus mainly on compliance at the point of hiring, and so miss the behavioural signals that only emerge years later.
At the same time, screening in the Netherlands operates within strict limits. The GDPR and employment law set boundaries on what an employer may investigate and monitor, and the Bibob Act applies only in specific situations. There is no licence for unlimited surveillance of your workforce. The most effective approach is to reserve the heaviest measures for the roles where the potential impact is greatest.

Limiting fraud along two tracks
The damage an insider can do is limited along two tracks: making fraud harder, and detecting it faster. Screening serves both. Before an appointment, an assessment is made of whether there are personal risks relevant to the role. Through periodic rescreening, you examine whether risks have emerged or grown over time — financial difficulties following a divorce, for instance.
The first track begins with strong basic controls: segregation of duties, clear authorisation limits, and four-eyes approval for payments, supplier management and contract sign-off. The second track is about actively looking rather than waiting. That means periodically checking the books against reality, examining payments, expense claims and unusual entries for patterns that do not add up, and carrying out unannounced audits with some regularity. In organisations that do this, fraud losses are roughly half as high and fraud is detected on average twice as quickly.⁶
The greatest damage arises where the most power sits, so that is where the strongest safeguards belong. In practice, that means:
- Independent screening that does not stop at the point of hiring, but is repeated periodically for high-risk roles and takes account of the signals that emerge over the course of a career.
- In-depth investigation where there is a concrete suspicion, looking beyond a standard check at financial pressure, conflicts of interest and susceptibility to influence.
- A fixed incident protocol: secure the evidence, block access and payments, and initiate legal and HR escalation as soon as a signal becomes serious.

Malicious from the outset?
An insider rarely starts out with malicious intent. Usually it is an accumulation: financial pressure at home, a role with too much unsupervised space, and an opportunity that presents itself. Fraud is then not a sudden lapse, but the outcome of signals that were often visible months earlier — had anyone been looking.
Which means that a check at the start of an employment relationship says little about who someone has become years later. For that reason, Dutch organisations would do well to keep their most trusted roles firmly in view — because that is where the greatest damage can originate.

Sources
¹ Association of Certified Fraud Examiners, "Occupational Fraud 2024: A Report to the Nations," maart 2024.
² Ibid.
³ Signpost Six, "Insider Risk Trend Report 2026," 2026.
⁴ Ibid.
⁵ Association of Certified Fraud Examiners, "Occupational Fraud 2024."
⁶ Ibid.
Stay ahead
subscribe to ourinsights
Subscribe to our monthly insights and receive the latest security insights straight to your inbox