The owner notices an unfamiliar vendor, asks the bookkeeper about it, and receives an explanation that raises three more questions. The temptation is to arrange a confrontation and demand the whole story. Before that conversation becomes the main event, the records need attention. An interview can be repeated. Yesterday’s accounting history may not be recoverable.
Stabilize the records and the payment controls
Suspicion is a reason to investigate, not a finding of theft. Duplicate payments, weak supervision, posting errors, and legitimate transactions with poor documentation can all look like misconduct. The first assignment is to preserve reliable evidence and find out what the transactions actually show.
The response needs coordinated roles. Counsel advises on the authorized legal scope, management supplies authorized access and operational knowledge, a digital forensic specialist handles any electronic collection that needs one, and the forensic accountant reconstructs the money. One person may cover several roles, but the roles should stay distinct.
Preservation and stopping further loss proceed together. Unauthorized payment access should not be left in place to achieve a perfect collection. Access changes need coordination so the business is protected while the relevant records and logs are captured where that is feasible.
There is no universal instruction to shut down every device or reset every account. The collection plan should identify the accounting system, banking portal, payroll system, email, document storage, and connected payment applications. Each may retain a different part of the transaction history.
A practical first conversation identifies who administers each of those systems, along with shared logins, recovery accounts, outside providers, and automatic deletion or retention settings. The bookkeeper may be the only person who knows those arrangements, which is exactly why an independent inventory is worth making.
Counsel can define the authorized scope of preservation before collection reaches personal devices, private accounts, or communications that need special handling. On the accounting side, I need a clear record of what was collected and where it came from. Possession of a password is not a collection plan.
The facts that raised the concern need preserving too. Original invoices, bank notices, emails, and contemporaneous notes separate what was known at the start from conclusions reached later. A reconstruction becomes harder to assess when the original concern changes with each retelling.
Collect the history behind the totals
A profit and loss statement is a summary of the books at one point in time. It does not show who created a vendor, changed a payment instruction, edited a transaction, or deleted an entry. Those details are central when the books themselves are under examination.
I want the accounting data in its original format or an available system export, together with the relevant audit history and attachments. A spreadsheet of current transactions may omit deleted items, earlier versions, document links, and important system fields. The collection should record those limitations.
Many accounting systems retain activity or audit history, but the available detail varies by product, user permissions, settings, and retention period. An unfamiliar user label or system event is a lead to investigate, not automatic proof that a particular person initiated the transaction.
Preserve original collected files separately from working copies, and document their source, date, custodian, and handling. That record helps the team distinguish the original data from later analysis or operational cleanup.
A login name identifies the account the system recorded, not necessarily the person at the keyboard. Shared credentials and automated integrations make that distinction important before anyone attaches a name to a transaction.
The business may still need corrected books to operate. Corrections should be documented and made through a controlled process after the original state has been preserved. Otherwise, well-intentioned cleanup removes the very differences the accountant needs to explain.
Follow bank evidence back through the books
Define the question population before testing anything in it. The full set of payments under review, whether it is every payment to one vendor, every disbursement over a threshold, or every transaction the bookkeeper entered in a period, should be identified, totaled, and fixed at the outset. Each item is then tested against that fixed list and given a disposition: supported, questioned, recovered, or still open. Items that clear the review are marked cleared; they are not removed. That discipline keeps the population from shrinking silently as the work proceeds, and it lets counsel see exactly which items were examined and why each was resolved as it was.
Bank records provide an independent reference for disbursements. Statements, check images, and electronic payment details show whether money left the business and help identify where it went. A ledger entry marked “paid” is not evidence that a payment cleared.
The next step connects each payment to an invoice, an approval, a business purpose, and evidence of delivery. For services, that may be work product, correspondence, schedules, or confirmation from people familiar with the work. An invoice with a plausible vendor name is one piece of a transaction, not the transaction.
The vendor master file deserves attention because it controls where many payments go. Changed bank details, addresses shared with employees, duplicate vendor records, and unusual payment patterns identify transactions for closer review. Each is a screening indicator, not a finding.
The review should be designed to test both money leaving the business and money that may never have reached the books. Diverted customer receipts, unauthorized refunds or credits, altered payroll, and payments posted to asset or loan accounts will escape a review limited to suspicious expense categories. A ledger can balance and still describe an improper transaction.
Interviews become useful when tied to specific records. Asking who approved a particular invoice or why a bank account changed is more informative than asking whether everything was handled properly. Explanations should be tested against independent records, including evidence that supports an innocent explanation.
A complete review also looks for reversals, duplicate entries, reimbursements, and amounts returned. They can materially change the result. Counting one payment in the bank data, the ledger, and an invoice list inflates the questioned amount without finding another loss.
Illustration: separate questioned payments from supported losses
Assume a hypothetical review identifies eighteen payments of $5,000 each to an unfamiliar vendor, a population of $90,000. The ledger descriptions are vague and the invoice file is incomplete. At this stage $90,000 is the amount requiring examination, not an established theft.
Further work verifies legitimate services behind six payments, or $30,000. The remaining twelve payments, $60,000, lack adequate support after the initial review. Bank records also confirm a $10,000 refund specifically attributable to the questioned payments.
The schedule shows $60,000 in questioned disbursements, a $10,000 related recovery, and $50,000 in unresolved net exposure, and it keeps the original $90,000 population visible so the reader can see which payments cleared and why. Nothing disappears because the investigation narrowed.
The $50,000 still needs work. Missing support does not prove no services were provided, and an unusual destination account does not by itself identify who benefited. Evidence of authorization, delivery, destination, and individual conduct determines how far the financial conclusion can go.
Assume later records establish that the remaining payments had no legitimate business purpose and reached an account benefiting an employee. The accountant can then explain the supported transactions and the unrecovered amount while counsel addresses the legal significance. Investigation costs, consequential losses, and any other claimed damages require their own analysis.
What to send
The initial package should preserve context as well as transaction data, so the team can begin without depending entirely on the system under review:
- A factual chronology of the concern, with the original supporting emails, invoices, notices, and notes.
- Accounting system data, available backups or exports, audit history, attachments, and the chart of accounts.
- Bank statements, check images, deposit details, and electronic payment destinations.
- Vendor records, payment instruction changes, invoices, approvals, and delivery or service evidence.
- Payroll registers, employee master records, reimbursement support, and change histories.
- User access lists, administrator information, connected applications, and retention settings.
- Customer receipts, refunds, credits, receivables detail, and merchant processing records where relevant.
- Collection records identifying sources, dates, custodians, and any preservation or access changes.
The first objective is a reliable transaction history from which a supported conclusion can develop. The best opening move is to preserve the transaction history, control further exposure, and let the evidence determine whether the issue is error, weak documentation, or misconduct.
This article is general information, not legal or financial advice. Every case turns on its own facts and on the law of the jurisdiction.
Have a matter that raises this question?
Start with a conflict check.
