28.3 Common Red Flags and Public Sector Fraud Schemes
Key Takeaways
- Major public sector fraud schemes include ghost employees, shell company vendors, fictitious invoices, duplicate billing transpositions, and split purchases engineered to bypass bidding thresholds.
- Forensic auditors must maintain strict chain of custody, execute structured multi-phase interviews, and promptly coordinate with Inspectors General or law enforcement upon establishing criminal indicators.
- Benford's Law mathematically detects anomalous frequency distributions in unconstrained accounting disbursements, while cross-database matching identifies improper employee-vendor overlaps.
Common Red Flags and Public Sector Fraud Schemes
Forensic auditors examine financial records for behavioral and transaction anomalies that serve as warning indicators of fraudulent activity.
Payroll Schemes: Ghost Employees and Unauthorized Alterations
A ghost employee is an individual listed on the government's payroll who does not actually work for the entity. The ghost may be a fictitious identity created by a payroll clerk or a former employee who resigned or was terminated but was intentionally kept on the active payroll register, with direct deposit payments diverted to the perpetrator's bank account.
- Audit Red Flags:
- Employee records with no deductions for federal taxes, health benefits, or state retirement systems
- Employees sharing a common physical residential address, bank routing number, or direct deposit account number with another active employee or payroll clerk
- Duplicate or invalid Social Security Numbers
- Employees with no recorded supervisory performance reviews, timesheet activity logs, or personnel files
- Continued payroll payments after official employee separation or retirement dates
Procurement & Disbursement Schemes
Procurement represents the single largest expenditure category vulnerable to public sector fraud:
- Shell Company Vendors: A corrupt employee establishes a fictitious business entity (often an LLC) with no physical operations, warehouse, or employees. The employee enters the shell company into the government's vendor master file, submits fabricated invoices for unrendered professional services (e.g., "Management Consulting" or "Strategic IT Planning"), and approves payments to a bank account or post office box under their control.
- Red Flags: Vendor address is a commercial mail drop or residential address; vendor registration date is immediately prior to first large contract award; vendor lacks a corporate website or telephone listing; vendor TIN is missing or formatted incorrectly.
- Sequential Invoice Numbering: Legitimate commercial vendors have multiple clients and issue non-consecutive invoices to any single customer. When a government receives consecutive invoice numbers from a vendor over a span of several months (e.g., Invoice #1001 in January, #1002 in February, #1003 in March), it is a major red flag indicating the government is the vendor's sole client—or that a shell company is generating fictitious invoices in sequence.
- Duplicate Billing and Transpositions: Corrupt or negligent vendors submit identical invoices multiple times. To bypass automated ERP duplicate invoice detection (which flags exact matches on vendor ID, invoice number, and dollar amount), perpetrators introduce deliberate transpositions or suffixes (e.g., submitting Invoice #4892, followed two weeks later by #4892-A, #4892B, or #4829 for the same dollar figure).
- Split Purchases (Structuring / P-Card Fraud): State statutes and municipal charters establish competitive bidding thresholds (e.g., formal sealed bids required for purchases exceeding $10,000). Dishonest procurement officers or purchasing card (P-Card) holders circumvent this control by intentionally splitting a large purchase into multiple smaller transactions just below the threshold (e.g., executing three separate purchases of $9,800 on consecutive days to buy $29,400 worth of equipment from a favored vendor).
| Fraud Scheme | Primary Vulnerability | Common Audit Red Flags | Recommended Forensic Test |
|---|---|---|---|
| Ghost Employee | Payroll master file access; lack of HR-payroll reconciliation | No benefit deductions; identical bank accounts; missing personnel file | Match payroll roster to active HR roster; verify physical presence. |
| Shell Company | Inadequate vendor vetting; single-user vendor approval | P.O. Box address; no web presence; consulting services with vague deliverables | Physical site inspection; verify corporate registration with Secretary of State. |
| Sequential Invoices | Discretionary service contracts; unverified billing | Invoices numbered sequentially over extended periods (e.g., #101, #102, #103) | Query vendor master file for invoice sequences; review vendor customer base. |
| Split Purchasing | Micro-purchase thresholds; P-Card approval limits | Multiple transactions just below bidding threshold from same department/vendor | Run transaction queries for amounts clustered within 10% below threshold. |
| Duplicate Billing | Lax invoice matching; manual invoice processing | Invoice numbers with suffixes (-A, -1); matching dollar amounts across dates | Automated query for matching vendor, amount, and date ranges. |
Advanced Forensic Testing: Benford's Law and Data Matching
Benford's Law (First-Digit Analysis)
Benford's Law (also called the First-Digit Law) is a mathematical phenomenon establishing that in naturally occurring, multi-digit numerical datasets, the distribution of leading digits follows a specific logarithmic curve rather than a uniform distribution (where each digit 1 through 9 would appear 11.1% of the time).
Where $d$ is the leading digit ($d \in {1, 2, \dots, 9}$).
| Leading Digit ($d$) | Theoretical Expected Frequency | Cumulative Probability |
|---|---|---|
| 1 | 30.1% | 30.1% |
| 2 | 17.6% | 47.7% |
| 3 | 12.5% | 60.2% |
| 4 | 9.7% | 69.9% |
| 5 | 7.9% | 77.8% |
| 6 | 6.7% | 84.5% |
| 7 | 5.8% | 90.3% |
| 8 | 5.1% | 95.4% |
| 9 | 4.6% | 100.0% |
When fraudsters fabricate numbers—such as inventing fake expense vouchers, fabricating travel claims, or forging construction invoices—they rarely replicate Benford's logarithmic distribution. Human beings instinctively create numbers starting with middle-to-higher digits (4, 5, 6, 7, 8, 9) and cluster amounts just beneath supervisory thresholds (e.g., repeatedly submitting claims starting with $4,900 when the approval threshold is $5,000).
- When Benford's Law APPLIES: Unconstrained, multi-order-of-magnitude financial records, such as municipal check registers, general ledger transaction values, full-year purchase card expenditures, and travel reimbursement claims.
- When Benford's Law DOES NOT APPLY: Assigned identification numbers (check numbers, ZIP codes, Social Security Numbers), datasets with rigid statutory minimums or maximums (fixed hourly wages of $15.00 to $22.00, or flat $50 parking fines), and populations with limited numerical spread.
Cross-Database Matching and Entity Resolution
Forensic auditors employ relational database queries to link disparate datasets, exposing hidden relationships between internal employees and external vendors:
- Employee-to-Vendor Matching: Executing inner joins between the employee master file and vendor master file matching on:
- Tax Identification Numbers (matching employee SSN to vendor TIN)
- Physical residential street addresses
- Bank account routing and transit numbers
- Telephone numbers Any match indicates an immediate conflict of interest, undisclosed self-dealing, or a potential shell company scheme.
- Public Assistance Roll Cross-Matching: Comparing public entitlement enrollment lists against state department of corrections incarceration records or the federal Social Security Administration's Death Master File to identify deceased or ineligible recipients collecting benefits.
Investigative Interviewing, Evidence Preservation & Law Enforcement Coordination
Phased Investigative Interviewing Techniques
Forensic interviews follow a disciplined, non-linear progression designed to gather facts, test consistency, and ultimately elicit admissions:
- Introductory / Rapport Phase: Establishing professional rapport, reviewing the interview's administrative purpose, and assessing the interviewee's normal baseline verbal and non-verbal behavioral cues.
- Informational Phase: Asking open-ended, non-threatening questions ("Can you walk me through the step-by-step process of how vendor invoices are received and approved in your division?") to collect operational details and identify control gaps.
- Assessment Phase: Introducing hypothetical or diagnostic questions to gauge integrity and reaction ("Why do you think someone in this department might bypass the competitive bidding requirements?").
- Admission-Seeking Phase: Reserved exclusively for the target subject when documentary evidence conclusively establishes wrongdoing. Conducted using direct, confident accusation while providing face-saving rationalizations to facilitate confession.
Evidence Preservation and Chain of Custody
Evidence gathered in a forensic audit must satisfy strict legal standards to ensure admissibility in court:
- Document Integrity: Original documents must be protected from contamination. Working copies should be used for daily audit testing. Forensic images of digital hard drives and server databases must be acquired using bit-stream, write-blocking forensic tools, generating verifiable SHA-256 hash checksums.
- Chain of Custody: A meticulous written record accounting for the chronological receipt, custody, transfer, analysis, and disposition of physical and electronic evidence. The log must document:
- Exact description and serial number of the item
- Identity of the person who collected it
- Exact date, time, and physical location of acquisition
- Secure storage facility location (e.g., locked evidence vault)
- Signatures of all individuals transferring and receiving custody
A break in the chain of custody can lead a trial judge to exclude critical financial records, destroying an otherwise sound criminal prosecution.
Coordination with Offices of Inspector General (OIG) and Law Enforcement
Auditors must understand the jurisdictional boundary between administrative auditing and criminal investigation. Under standard governmental auditing guidelines, when an auditor uncovers clear indicators of criminal activity (bribery, kickbacks, forgery, wire fraud):
- Cease Routine Auditing: The auditor must immediately pause routine inquiries and contact legal counsel and the designated Office of Inspector General (OIG) or law enforcement authority.
- Avoid Alerting Subjects: Continuing routine audit testing after discovering criminal fraud risks tipping off the perpetrator, leading to document destruction, witness tampering, or flight.
- Maintain Workpaper Confidentiality: Protect investigative working papers from premature public records disclosure (e.g., FOIA requests) under statutory law enforcement investigatory exemptions.
A forensic auditor examines a city's annual accounts payable check register containing 25,000 disbursement records totaling $85,000,000. When testing the dataset against Benford's Law, which of the following observations would represent a strong mathematical anomaly warranting immediate forensic scrutiny?
An internal audit of a state transportation agency uncovers a series of 15 invoices from a single vendor across six months. All invoices are for consulting services, are sequentially numbered (#201 through #215), and each invoice is billed for exactly $9,750, where agency policy mandates formal competitive sealed bidding for any procurement exceeding $10,000. What specific fraud schemes and red flags do these circumstances primarily demonstrate?