There is a line item missing from every budget in the country: the fraud tax. The Association of Certified Fraud Examiners, the global body of certified fraud specialists, has measured occupational fraud for nearly three decades across hundreds of thousands of investigated cases, and its central estimate barely moves. The typical organization loses about 5% of revenue each year to fraud committed by its own people.
This article is about what that number means in rands and cents, why the median scheme runs for a year before anyone notices, and why the controls that actually move it are governance controls rather than software purchases.
At a glance
- 5% of annual revenue: the ACFE’s long-run estimate of occupational fraud losses, built on 2,402 investigated cases totalling more than R54 billion in losses in the 2026 Report to the Nations.
- The median scheme runs 12 months before detection, at a median cost of about R1.7 million ($104,000); schemes that survive five years or more average well over R18 million.
- Tips detect 43% of fraud, more than internal audit and management review combined, and 55% of those tips come from the organization’s own employees.
- 84% of perpetrators displayed at least one behavioural red flag before detection, and the overwhelming majority were first-time offenders with clean records.
The Arithmetic Nobody Budgets For
Five percent of revenue is the number that should stop the meeting. For a company turning over R200 million a year, it is R10 million annually, lost invisibly: padded suppliers, ghost invoices, expense abuse, procurement kickbacks, diverted payments. The ACFE’s 2026 Report to the Nations analysed 2,402 real cases with combined losses of more than R54 billion. The median scheme cost about R1.7 million; the average ran above R22 million, dragged up by the catastrophic tail. And the ACFE itself calls the 5% estimate conservative, because it excludes what follows discovery: investigation, litigation, reputational damage, and the morale bill.
South Africans do not need to import the idea. Steinhoff’s accounting collapse, Tongaat Hulett’s restatement, and the roughly R2 billion looted from VBS Mutual Bank were occupational fraud on a grand scale, and they reshaped pensions, municipalities, and markets. The 5% estimate is not an abstraction here. It is the polite version of a very local history.
Fraud appears in no budget line because it is, by definition, hidden. That is precisely why executives should estimate it deliberately. The organization that accepts the statistical reality can price its prevention accordingly; the organization that refuses the statistic pays the number anyway, without the prevention.
The Fraud Triangle: Why Ordinary People Do It
Occupational fraud stands on three legs, and every scheme needs all of them. Pressure: the debt, the target, the lifestyle that starts the engine. Opportunity: the control gap that makes the act possible. Rationalization: the story people tell themselves so it does not feel like stealing. Note what is absent from the triangle: a criminal profile. The overwhelming majority of perpetrators are first-time offenders with clean employment records, which means background checks, the industry’s favourite preventive purchase, catch almost none of them.
Governance cannot reach into somebody’s private pressure, and it rarely wins an argument with a rationalization. But opportunity is entirely within its gift. Segregation of duties, vendor master hygiene, payment verification, mandatory leave, and reconciliation discipline remove the leg the scheme needs to stand on. Fraud is a governance problem before it is a technology problem, precisely because opportunity is a governance product.

A Year on the Job Before Anyone Notices
The median occupational fraud scheme runs twelve months before detection. That is not because the signs are absent: 84% of perpetrators displayed at least one behavioural red flag, living beyond visible means the most common at 39%. It is because nobody is positioned, or encouraged, to connect the flag to the possibility. Detection timing is the single biggest driver of loss. Schemes caught within six months carry a median loss of roughly R650,000. Schemes that survive five years average more than R18 million. Fraud compounds in the dark.
Seniority multiplies the damage. Owner and executive-level fraud produces a median loss of about R7.6 million, more than nine times the staff-level median of roughly R800,000, because senior people combine trust, access, and the authority to override the very controls designed to catch them. The higher the chair, the stronger the controls around it need to be, which is a conclusion many boards find inconvenient and the data finds unavoidable.
How Fraud Is Actually Found
Ask a board how fraud would be detected in their organization and the answer is usually audit. The data has disagreed in every edition of the ACFE’s research since 1996. Tips detect 43% of schemes. Internal audit finds 15%, management review 13%, and external audit low single digits. More than half of the tips, 55%, come from the organization’s own employees. The control that finds most fraud is a culture in which people can report what they see, safely, and do.

The presence of proper reporting channels changes the economics measurably. Organizations with formal intake mechanisms suffer a median loss of about R1.6 million against R2.4 million for those without, and they cut their median detection time from 17 months to 11. A reporting channel is not a compliance ornament. It is the statistically proven best fraud control money can buy, and it costs almost nothing.
The Controls That Move the Numbers
The ACFE dataset also prices the controls that shorten a scheme’s life. Surprise audits are associated with a 50% reduction in median losses. Proactive data monitoring and analysis, 53%. Management review, 55%. The pattern across all of them is consistent: what works is what interrupts opportunity and shortens duration. Controls that document intent, by contrast, protect the file rather than the money. This is the assurance gap in fraud form: a segregation-of-duties rule nobody tests is an open door with a policy pinned to it.
Technology has a role, in transaction monitoring and anomaly detection, but it is the seasoning, not the meal. The organizations that lose least run unglamorous governance relentlessly: duties genuinely separated, bank-detail changes verified by callback, vendor masters cleaned quarterly, and reconciliations signed by someone who asks questions.
What Leaders Should Do Now
1. Price the 5% honestly. Put the statistical estimate of fraud exposure on the table next to the cost of controlling it, and let the arithmetic make the case for the programme.
2. Stand up a real reporting channel and market it. Web intake, anonymity, and visible follow-through. Then measure staff awareness of it, because an unknown channel detects nothing.
3. Attack the opportunity leg. Segregation of duties, verified callbacks for every bank-detail change, vendor master hygiene, and mandatory leave for people in payment paths.
4. Shorten the clock. Data monitoring plus surprise audits. The difference between a R650,000 incident and an R18 million one is twelve months of nobody looking.
5. Train managers on the red flags. Four in five perpetrators showed at least one. The cheapest detection upgrade available is teaching your leadership team to recognize what they are already seeing.
Sources: ACFE Report to the Nations 2026; ACFE occupational fraud statistics 2024 to 2026; Prudential Authority of South Africa, The Great Bank Heist report (VBS Mutual Bank).
Fraud finds the gaps, and the gaps are governance gaps: unverified bank details, untested duties, unwatched vendors, and unreported suspicions. Lebone Marang and Summer’s Fraud Prevention Platform works those gaps end to end, from fraud risk assessment through to independent investigation. If you cannot say today where fraud would find a way into your organization, that is the conversation to have before it does.




