← University
Commercial Fraud and Remedies
0 of 4

A discrepancy in inventory records first surfaced during a routine quarterly review at a small wholesale distribution company operating out of a warehouse facility in southern Ontario. The company, which had been in business for 11 years distributing industrial cleaning supplies to commercial clients across the province, had maintained a relationship with a particular chemical supplier for nearly 7 of those years. The supplier, a privately held manufacturing operation based in a neighbouring region, had consistently provided competitive pricing, reliable delivery schedules, and what appeared to be authentic product certifications for the industrial-grade cleaning compounds the distributor resold to its clients.

The inventory discrepancy prompted the distributor's owner to examine purchase records more closely. Over the following 3 weeks, a troubling pattern emerged. Invoices from the supplier over the preceding 18 months reflected quantities and prices that did not align with shipping manifests, and several product certification documents bore irregularities that had not been noticed when the documents were originally received. The owner engaged an accountant to conduct a more thorough review, which revealed that the apparent overcharges and phantom deliveries amounted to approximately $187,000 over the 18-month period. Further investigation suggested that at least some of the product certifications provided by the supplier may have been fabricated, raising questions about whether the distributor had unknowingly resold improperly certified products to its own commercial clients.

The distributor's owner now faces a series of consequential decisions. The company holds a commercial insurance policy that includes some coverage for business losses, though the policy language regarding fraud is ambiguous. The owner has consulted briefly with a lawyer who indicated that both civil and criminal avenues might be available, but pursuing either would require time, documentation, and resources the small business can ill afford to divert from operations. The supplier, for its part, has not responded to written inquiries seeking an explanation for the discrepancies. Meanwhile, the distributor must consider its own potential exposure to claims from the commercial clients who purchased the products in question, as well as what immediate steps might be necessary to preserve evidence, protect ongoing business relationships, and mitigate further losses. The company's existing internal controls, which had been developed informally over the years without legal guidance, are now under scrutiny as well.

Practical Prevention and Response: What Businesses Should Do

Commercial fraud represents one of the most significant threats to Canadian businesses, yet many owners and operators remain underprepared until they become victims. The preceding lessons in this course have examined the nature of commercial fraud, the legal frameworks that define it, and the remedies available when fraud occurs. This final lesson shifts focus to the practical dimension that matters most for business owners: how to prevent fraud before it happens and how to respond effectively when it does. Prevention and response are not merely matters of good practice but carry legal significance in their own right, affecting everything from insurance coverage to the availability of civil remedies and, in some circumstances, potential liability for failing to maintain adequate safeguards.

The legal foundation for fraud prevention in Canadian business rests on several intersecting frameworks. The Criminal Code establishes fraud as an indictable offence and creates obligations for businesses to report certain types of fraudulent activity, particularly where it involves financial institutions or securities. The Personal Information Protection and Electronic Documents Act, as of the date of authorship, requires federally regulated businesses and those engaged in commercial activity across provincial boundaries to maintain security safeguards appropriate to the sensitivity of the personal information they hold, which creates an implicit duty to prevent fraud targeting that information. Provincial privacy legislation in British Columbia, Alberta, and Quebec imposes similar obligations within those jurisdictions. Beyond these statutory requirements, common law principles of negligence can impose liability on businesses that fail to implement reasonable fraud prevention measures, particularly where their negligence facilitates fraud against third parties such as customers or business partners. In Quebec, the Civil Code of Quebec establishes comparable duties through its provisions on extra-contractual liability, requiring persons to conduct themselves according to the rules of conduct incumbent upon them according to the circumstances, usages, or law.

Business owners must understand that fraud prevention is not a one-time activity but an ongoing operational responsibility. Courts and regulators across Canada have consistently recognized that reasonable prevention measures must evolve with the threat landscape. What constituted adequate security for online payment processing in 2015 would be considered grossly inadequate today. This means that businesses face a continuing obligation to review and update their fraud prevention measures, and failure to do so can have consequences ranging from denial of insurance claims to potential civil liability and regulatory penalties.

The practical reality of fraud prevention begins with understanding where vulnerabilities exist. Every business handles money, information, or both, and these create the primary targets for fraudsters. Payment fraud encompasses schemes ranging from sophisticated business email compromise attacks to straightforward cheque forgery. Information fraud includes identity theft targeting customer data, trade secret theft by employees or competitors, and manipulation of business records for financial gain. Operational fraud covers schemes involving fake vendors, fictitious employees on payroll, or manipulation of inventory and shipping records. Each category requires distinct prevention strategies, though certain foundational practices apply across all contexts.

Internal controls represent the cornerstone of fraud prevention for businesses of every size. These controls create systems of checks and oversight that make fraud more difficult to commit and easier to detect. The principle of segregation of duties holds that no single person should control all aspects of any significant transaction. A person who can authorize a payment should not also be the person who reconciles the bank account. Someone who receives inventory should not also be responsible for updating inventory records and authorizing purchases. For small businesses where limited staff makes complete segregation impossible, compensating controls become necessary, such as requiring owner review of bank statements, maintaining strict limits on individual transaction authority, or implementing surprise audits. Documentation requirements ensure that transactions create paper trails that can be reviewed and verified. Authorization hierarchies establish clear rules about who can commit the business to various types and sizes of transactions.

Technology has transformed both the fraud threat and the available defenses. Modern payment systems offer security features that businesses should actively utilize rather than treat as optional conveniences. Multi-factor authentication for financial accounts, positive pay services that verify cheques before honouring them, dual authorization requirements for electronic transfers above specified thresholds, and encrypted communications for sensitive financial information all represent readily available tools. Email security measures including domain authentication protocols help prevent business email compromise attacks where fraudsters impersonate executives or vendors. Access controls on business systems should follow the principle of least privilege, granting employees access only to the systems and information necessary for their specific roles.

Employee-related fraud presents particular challenges because it involves breaches of trust by people with legitimate access to business systems and assets. Prevention begins with hiring practices including appropriate background checks and verification of credentials and references. The Proceeds of Crime (Money Laundering) and Terrorist Financing Act imposes specific know-your-client obligations on designated businesses including financial services providers and money services businesses, but the principle of verifying the identity and background of those given positions of trust applies broadly. Clear policies regarding conflicts of interest, acceptable use of business resources, and reporting of suspected misconduct establish expectations and provide grounds for disciplinary action. Exit procedures when employees leave should include prompt termination of system access, return of business property including access cards and keys, and review of recent transactions for irregularities.

Vendor and supplier relationships create another significant fraud exposure. Fictitious vendor schemes, where someone creates fake supplier accounts and directs payments to themselves, remain among the most common forms of internal fraud. Prevention requires verification of new vendors through independent research rather than reliance on information provided by the vendor, including confirmation of business registration, physical location, and banking information through direct contact using independently verified contact information. Changes to vendor banking information warrant particular scrutiny, as fraudsters commonly attempt to redirect legitimate payments by convincing businesses to update their records with fraudulent account details. Regular review of vendor master files to identify dormant accounts, duplicate entries, or vendors with suspicious characteristics helps detect schemes before losses accumulate.

Consider the experience of a wholesale distribution company operating from a warehouse facility in Mississauga with satellite operations in Calgary and Halifax. The company employed approximately forty-five people including a bookkeeper who had worked with the business for over twelve years and enjoyed the complete confidence of the owner. The bookkeeper handled accounts payable, accounts receivable, bank reconciliations, and payroll administration. Over a period of approximately four years, this trusted employee embezzled roughly $680,000 through a combination of schemes including creation of a fictitious vendor that purportedly supplied cleaning and maintenance services, manipulation of payroll to add hours for a relative who did not actually work for the company, and personal purchases made on the company credit card but recorded as legitimate business expenses. The fraud was discovered only when the owner, dealing with what he believed was a temporary cash flow problem, began personally reviewing financial records and noticed the fictitious vendor had been paid approximately $8,500 monthly for services he knew the company did not receive. Subsequent investigation revealed the full scope of the embezzlement.

This situation reveals several critical lessons about fraud prevention. The concentration of financial responsibilities in a single trusted employee created the opportunity for fraud. The owner's complete delegation of financial oversight meant no independent review occurred for years. The business had no policy requiring vacation, which might have exposed the fraud when someone else performed the bookkeeper's duties. Purchase documentation was not independently verified, allowing personal purchases to be recorded as business expenses. Banking records were reconciled by the same person who initiated transactions, eliminating the check that comparison might have provided. Each of these deficiencies represented a failure of basic internal control principles that even a small business can and should implement.

The financial impact extended beyond the direct loss. The company's commercial insurance policy excluded employee theft because the business had never added crime coverage, an additional premium option the owner declined years earlier without fully understanding what protection it provided. The employee had no significant assets that could satisfy a civil judgment, making recovery through litigation unlikely despite clear liability. The business faced a genuine solvency crisis that required the owner to inject personal funds and renegotiate terms with major creditors. The emotional toll on the owner, who had trusted the employee implicitly and considered her part of the business family, compounded the financial damage.

When fraud does occur despite prevention efforts, the response must be swift, systematic, and properly documented. The initial response when fraud is suspected should focus on containment and preservation. Containment means stopping ongoing losses by suspending access, freezing accounts where possible, and preventing further unauthorized transactions. Preservation means securing evidence before it can be destroyed or altered, including electronic records, documents, communications, and physical evidence. The importance of avoiding premature confrontation or accusations cannot be overstated. Alerting a suspected fraudster before evidence is secured often results in destruction of records, disappearance of assets, and sometimes flight of the perpetrator.

Documentation created during the investigation becomes crucial for subsequent legal proceedings, whether criminal prosecution, civil recovery, or insurance claims. A contemporaneous record of what was discovered, when it was discovered, and by whom provides the foundation for all subsequent actions. Businesses should establish clear chains of custody for physical and electronic evidence, noting who handled materials and when. Communications regarding the investigation should be in writing where possible and carefully preserved.

The decision whether to involve law enforcement requires careful consideration. Reporting fraud to police creates a public record and may result in criminal prosecution, but business owners should understand that criminal proceedings serve public interests rather than the victim's recovery interests. Prosecutors are not obligated to consider what outcome would best serve the business's financial recovery, and criminal restitution orders, while available, often prove difficult to enforce against defendants with limited assets. However, failing to report can have its own consequences including potential issues with insurance claims that require evidence of criminal conduct and, in some circumstances, statutory reporting obligations. The Proceeds of Crime (Money Laundering) and Terrorist Financing Act requires designated entities to report suspicious transactions, and provincial securities legislation imposes reporting obligations in securities-related fraud. Business owners should seek legal advice before making decisions about law enforcement involvement.

Civil litigation for fraud recovery involves considerations distinct from criminal proceedings. The burden of proof in civil cases is balance of probabilities rather than the criminal standard of beyond reasonable doubt, making successful litigation more likely in marginal situations. Civil proceedings also offer remedies unavailable in criminal courts, including tracing and recovery of specific assets, constructive trusts over property acquired with stolen funds, and Mareva injunctions to freeze assets pending trial. In Quebec, similar protective measures are available through the provisional measures provisions of the Code of Civil Procedure. However, civil litigation is expensive, time-consuming, and worthwhile only where the defendant has assets sufficient to satisfy a judgment. Practical judgment about recovery prospects should inform litigation decisions.

Insurance claims following fraud require careful attention to policy terms, notice requirements, and documentation. Crime coverage, fidelity bonds, and cyber insurance policies each address different types of fraud losses, and many businesses discover only after a loss that their coverage does not extend to the situation they face. Policy exclusions commonly limit coverage where the insured failed to maintain specified internal controls, where the fraud was committed by an owner or partner, or where losses were not discovered within specified periods. Notice requirements typically impose strict deadlines for reporting losses, and failure to provide timely notice can void coverage entirely. Cooperation obligations require policyholders to assist insurer investigations and may require filing police reports. Business owners should review their coverage before fraud occurs to understand what protection they actually have and what conditions they must satisfy to maintain it.

Regulatory notifications may be required following certain types of fraud. Privacy breach notification obligations under the Personal Information Protection and Electronic Documents Act, as of the date of authorship, require organizations to notify affected individuals and the Privacy Commissioner when a breach of security safeguards involving personal information creates a real risk of significant harm. British Columbia, Alberta, and Quebec have provincial requirements that may also apply. Securities regulators must be notified of certain fraud affecting reporting issuers. Financial institutions have their own regulatory notification obligations that may indirectly affect business customers.

Recovery from fraud extends beyond financial recoupment to include operational recovery. Businesses must rebuild damaged systems and controls, address any regulatory concerns arising from the incident, manage reputational impacts, and often deal with disruption to normal operations during the investigation and remediation period. Planning for this recovery phase, including maintaining business continuity during investigation, should be part of fraud response planning undertaken before any incident occurs.

Practical steps that every Canadian business can implement include establishing written financial policies covering authorization limits, payment procedures, and segregation of duties appropriate to the business size. Business owners should review bank statements and credit card statements personally, regardless of who performs routine bookkeeping. Vendor verification procedures should require independent confirmation of new suppliers and any changes to payment information. Employee background checks appropriate to the position, including reference verification, should be standard practice for positions involving financial responsibility or access to sensitive information. Insurance coverage should be reviewed annually with specific attention to crime coverage, cyber coverage, and any conditions or exclusions that might affect claims. Response plans should identify who will do what if fraud is detected, including legal counsel to contact, forensic resources available, and notification requirements. Regular audits or reviews, whether formal external audits or informal owner reviews, provide ongoing monitoring. Questions that business owners should regularly ask themselves include whether anyone in the organization could commit significant fraud without detection, whether they would know within days if someone began stealing from the business, and whether their insurance actually covers the fraud scenarios most likely to affect their operation.

The investment in fraud prevention rarely feels urgent until fraud occurs. Businesses that have experienced significant fraud universally report that the cost of prevention would have been trivial compared to the losses they suffered. Beyond the direct financial impact, fraud damages business operations, consumes management attention, strains relationships with customers and suppliers, and creates legal exposure that persists long after the initial incident. Prevention is not merely prudent business practice but increasingly an expectation that courts, regulators, and insurers build into their assessment of how businesses should operate. For Canadian business owners and operators, understanding both prevention strategies and response procedures represents essential knowledge for protecting the enterprises they have built.

Continue with University access

This lesson is part of a $79 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options