Most finance professionals have heard of the Clive Peters fraud. It happened almost 20 years ago, yet the control failures behind it remain surprisingly common.
Over a two-year period, more than $19 million was stolen through falsified payroll transactions. Eventually the fraud contributed to the collapse of the retailer, but the amount stolen is only part of the story.
What makes this case so relevant today is not the fraud itself. It's the way it happened. The employee responsible wasn't exploiting sophisticated technology or breaking into systems. They were using legitimate access that had gradually expanded over time. They could move money, alter records and explain the discrepancies when questions were asked.
That combination should never exist.
More approvals weren't the answer
Whenever a major fraud is uncovered, organisations often respond in the same way. They add another approval. Another review. Another checklist.
The Clive Peters case shows why that approach isn't enough.
If the same person controls both the transaction and the evidence used to justify it, additional approvals simply provide another opportunity to approve incorrect information. What looks like strong governance can actually be little more than false assurance.
The better question is not "Who approved the payment?"
It's "Where did the evidence come from, and can it be trusted?"
Trust and controls are not the same thing
One of the recurring themes in major fraud investigations is that the people involved are often trusted employees.
That's understandable. Organisations need to trust their people.
But trust should never replace good control design.
Finance leaders should regularly review who has the ability to create supplier records, amend payroll information, change bank accounts, release payments, perform reconciliations and investigate exceptions. Individually, each responsibility may be perfectly reasonable. Combined, they can create unnecessary risk.
This isn't about assuming people will do the wrong thing. It's about ensuring no one has the opportunity.
The warning signs were there
One of the most interesting aspects of this case is that the warning signs weren't hidden.
Management believed the business was under pressure and accepted that poor retail conditions explained the financial results. Once that explanation became accepted, every new anomaly seemed to reinforce the same conclusion rather than challenge it.
That's confirmation bias, and it affects every organisation.
It's why independent verification matters so much. Good controls don't simply report what happened. They challenge assumptions before they become accepted as fact.
Evidence matters more than reports
The fraud was eventually uncovered when someone compared operational records against backup records that hadn't been altered. That independent comparison exposed what months of internal reviews had missed.
It's a reminder that reports are only as reliable as the data behind them.
Finance teams should be asking practical questions such as:
- Can bank account changes be independently verified?
- Are payment files preserved in an unalterable form?
- Can reports be modified after they've been reviewed?
- Are unusual payment patterns detected automatically?
- Could someone reconstruct every payment using independent evidence?
These questions are becoming increasingly important as organisations automate more of their finance function.
Continuous monitoring is becoming essential
Modern finance teams process thousands, sometimes millions, of transactions every month.
No manual review process can keep pace.
That's why continuous monitoring is becoming a standard part of good financial governance. Rather than relying on periodic reviews, organisations can identify unusual bank account changes, manual journals, segregation of duties conflicts and payment anomalies as they occur, allowing issues to be investigated before funds leave the business.
The technology has changed considerably since the Clive Peters fraud, but the underlying principles haven't.
Good governance still comes back to the same fundamentals.
Separate responsibilities. Verify independently. Preserve evidence. Challenge assumptions.
Because when someone can control the transaction and the evidence, the organisation isn't just exposed to fraud, it may not even realise it's happening.