Insights

Fraud Is Outpacing Governance And The Data Is No Longer Subtle

Fraud rarely explodes overnight. It embeds quietly inside growth decisions, digital acceleration and blurred accountability. Global research shows organisations lose an estimated 5% of annual revenue to fraud, with schemes lasting over a year before detection. In South Africa’s rapidly evolving digital and procurement landscape, the question is no longer whether fraud exists — but whether governance is evolving fast enough to see it early.

MK Fraud Insights28 February 20264 min read
Fraud StrategyFraud GovernanceSouth AfricaExecutive Risk LeadershipDigital Risk

There is a quiet confidence that settles into organisations when fraud numbers look “stable.” Losses are within tolerance. Audit findings are manageable. No media exposure. No regulator at the door. On paper, everything appears contained.

But when you step outside the internal dashboard and look at the global and local data, the picture shifts.

The Association of Certified Fraud Examiners (ACFE) estimates that organisations lose approximately 5% of their annual revenue to fraud each year (ACFE, 2022). That statistic alone should unsettle any executive team. More concerning is the median duration of fraud schemes — roughly 12 to 18 months before detection. In other words, fraud does not erupt overnight. It embeds itself quietly and persists long before it is discovered.

That detection lag is not a small operational issue. It is a structural exposure.

In South Africa, the pattern is consistent with global trends but amplified by context. PwC’s Global Economic Crime and Fraud Survey consistently shows high levels of economic crime in the country, particularly cyber-enabled fraud, procurement manipulation and customer fraud (PwC, 2022). Overlay this with rapid digital adoption, platform growth and mobile financial integration, and the risk surface area expands faster than most governance frameworks evolve.

The problem is not that fraud is new.

The problem is that complexity is accelerating faster than oversight.

Digital transformation has been framed as a competitive necessity. Faster onboarding. Instant approvals. Seamless refunds. Loyalty integration across channels. Embedded payments. Marketplace models. Each of these improvements removes friction — and friction used to be where fraud was slowed down.

Research across fintech and digital banking ecosystems shows that as transaction speed and automation increase, fraud attempts scale accordingly. Criminal networks adapt to process design. They test onboarding thresholds. They study refund logic. They exploit loyalty accrual rules. They probe API integrations. They do not need to outsmart the entire system; they only need to identify the smallest governance hesitation.

In environments where growth metrics dominate performance discussions, fraud risk often becomes a secondary conversation — addressed once losses become visible. Yet by that stage, the scheme has usually matured.

The ACFE’s findings also show that occupational fraud remains persistent and costly, with corruption and asset misappropriation among the most common forms (ACFE, 2022). Seniority correlates with higher median losses. Tenure often correlates with longer undetected schemes. Fraud is not only a technological vulnerability; it is an organisational one. Authority and trust, when unchecked by structured oversight, create opportunity.

In South Africa, the recurring public sector irregular expenditure figures, procurement investigations and state capture inquiries demonstrate how governance weaknesses compound over time. While the private sector experiences similar risks, they are less frequently publicised. Vendor collusion, override abuse, insider-assisted fraud and loyalty manipulation rarely make headlines — but they quietly erode margins and credibility.

Another uncomfortable data point emerges when we examine detection sources. Globally, fraud is most commonly detected through tips rather than analytics (ACFE, 2022). That should cause pause. It suggests that human observation often outpaces system monitoring. If complaints and whistleblowing remain primary detection mechanisms, then many organisations are operating reactively rather than predictively.

This is not a criticism of fraud teams. It is a structural observation.

Banks have invested heavily in fraud capability over decades due to regulatory scrutiny and direct financial exposure. Outside traditional financial services, maturity levels vary widely. In retail, telecoms, public entities and hybrid platforms, fraud ownership is often diffused across audit, compliance, operations or security. Without clear executive accountability, funding and capability development become inconsistent.

And inconsistency is where fraud adapts.

The Companies Act (2008) places fiduciary duties on directors to act in the best interests of the company, which implicitly includes oversight of material risks. PRECCA (2004) and POCA (1998) reinforce accountability around corruption and proceeds of unlawful activity. Yet legislative frameworks alone do not create capability. Governance must be operationalised through design, ownership and strategic clarity.

The central tension becomes clear: organisations are integrating more systems, more third parties and more digital channels than ever before. Each integration creates a trust boundary. Each trust boundary introduces exposure. Without deliberate design, those boundaries become blind spots.

Fraud is not merely increasing because criminals are more sophisticated.

Fraud is increasing because organisational ecosystems are becoming more complex, while governance conversations often remain functionally siloed.

If the average fraud scheme lasts more than a year before detection, then every executive team must confront a difficult question:

What is happening inside our environment right now that we have not yet seen?

And who, specifically, owns finding it before it escalates?

Fraud is not only a loss issue.

It is a governance maturity indicator.

And the data is no longer subtle about that reality.

References

Association of Certified Fraud Examiners (ACFE). (2022). Report to the Nations: Global Study on Occupational Fraud and Abuse.
PwC. (2022). Global Economic Crime and Fraud Survey.
Prevention and Combating of Corrupt Activities Act 12 of 2004 (South Africa).
Prevention of Organised Crime Act 121 of 1998 (South Africa).
Companies Act 71 of 2008 (South Africa).