Why this decision matters
The typical small business fraud is not a stranger's cyberattack; it is a long-serving, trusted employee with sole control of a financial process — payments, deposits, payroll, or the bank reconciliation — exploiting the absence of a second pair of eyes, often for years.
Small firms are structurally exposed because one person often does everything. The remedy is not suspicion of people; it is the design of process — making sure no single person can both commit and conceal.
The central idea
Fraud requires committing and concealing. Separate those two capabilities and most schemes become impossible.
Segregation of duties is the master control: the person who enters bills should not approve payments; the person who approves payments should not reconcile the bank; the person who runs payroll should not be able to add employees unreviewed. In a five-person office, perfect separation is impossible — but owner participation substitutes: the owner reviews bank activity weekly (directly in the bank portal, not through reports prepared by the person being checked), approves every new vendor and every payee change, and signs off on payroll summaries.
Around that core, a short list of controls covers most schemes: dual authorization on electronic payments above a set threshold; call-back verification on any emailed change to banking details — the signature move of payment-diversion fraud; mandatory vacations with duties actually reassigned; surprise counts where cash or inventory matters; and a culture where the owner's visible engagement with the numbers is itself a deterrent. Report incidents to police and the Canadian Anti-Fraud Centre — silence protects the next fraudster.
Educational use notice
This publication is part of the Numera Decision Library and is provided for education only. It is general information — not accounting, tax, legal, or investment advice — and it does not consider your personal circumstances. Every guide is grounded in official guidance from government and regulated authorities — including the Canada Revenue Agency (CRA), the Department of Finance Canada, Service Canada and Employment and Social Development Canada, the Internal Revenue Service (IRS), and the Canadian Centre for Cyber Security — with the sources listed at the end of each guide. Tax rules and dollar limits change; confirm current figures with the official source, and speak with a qualified professional before acting on any decision discussed here.
Official references
Sources are official government and regulated-authority publications. Official sites reorganize periodically — search the document title if a link has moved.