Krishna Priyan

Risk, Fraud & Governance

Risk Management, Fraud Prevention & Governance

The Domino Theory of Business Risk: How One Missing Approval Can Trigger a Chain Reaction of Business Failures

Imagine lining up fifty dominoes in a straight line. Each domino stands independently. At first glance, knocking over the first one seems insignificant. It’s just one small movement. But the moment the first domino falls, it transfers its energy to the next. Then the next. Then another. Within seconds, every domino is lying flat. Now imagine replacing those dominoes with business processes. The first domino isn’t made of plastic. It’s a missing approval. The last domino isn’t another process. It’s lost revenue. This is what I call The Domino Theory of Business Risk. In most organizations, catastrophic failures rarely begin with catastrophic mistakes. They begin with one seemingly insignificant control failure that quietly triggers a chain of consequences. Businesses Don’t Fail Overnight When companies experience major operational disruptions, leadership often focuses on the final outcome. Production stopped. Customers complained. Revenue declined. Market share dropped. But these are rarely the starting point. They’re simply the last domino to fall. The real question isn’t: “Why did revenue decline?” It’s: “Which domino fell first?” Internal auditors understand that business risk is cumulative. Every process depends on another process. Every decision influences another decision. Small failures don’t stay small. They travel. The First Domino: One Missing Approval Consider a simple procurement process. A purchase order requires approval before raw materials can be ordered. One manager is unavailable. The approval waits. “It can wait until tomorrow,” someone says. After all, it’s just one approval. Or is it? Domino Two: Late Purchase Order Without approval, procurement cannot release the purchase order. The supplier doesn’t receive confirmation. Materials aren’t dispatched. Nothing dramatic has happened yet. But momentum has already shifted. The first domino has fallen. Domino Three: Late Vendor Payment Because procurement was delayed, invoices arrive later than expected. Payment schedules change. The finance department misses the agreed payment date. From the organization’s perspective, it’s only a few days. From the vendor’s perspective, it’s a breach of trust. Relationships begin to weaken. Domino Four: Vendor Dispute Reliable suppliers value predictability. Repeated payment delays create uncertainty. The vendor responds by: The issue is no longer about one payment. It has become a relationship problem. Domino Five: Production Delay Now production enters the picture. Without raw materials, manufacturing slows. Production schedules shift. Employees wait. Machines remain idle. Overtime costs increase. Management scrambles to find alternative suppliers. The missing approval has now crossed departmental boundaries. A finance issue has become an operational issue. Domino Six: Customer Dissatisfaction Customers don’t see procurement delays. They don’t know about approval bottlenecks. They only experience one thing: Their order wasn’t delivered on time. Late deliveries lead to: Customers judge organizations by outcomes, not explanations. Domino Seven: Revenue Decline Eventually, the financial statements begin reflecting the consequences. Revenue decreases. Profit margins shrink. Operating costs rise. Cash flow becomes strained. Management launches cost-cutting initiatives. Ironically, the entire sequence began with one delayed approval that seemed insignificant. The final domino rarely reveals the first. Why Organizations Focus on the Wrong Domino When revenue falls, companies often react by increasing sales targets or reducing expenses. While these actions may provide temporary relief, they don’t address the underlying issue. Imagine standing at the end of the domino line and trying to stop the last domino after the first forty have already fallen. It’s too late. Risk management isn’t about catching the final domino. It’s about preventing the first one from falling. Business Risk Is Interconnected Many organizations manage risks in isolation. Finance manages financial risk. Operations manages operational risk. IT manages cybersecurity. Procurement manages suppliers. Human Resources manages people. But business doesn’t operate in isolated departments. Every department is connected. A failure in procurement affects production. Production affects logistics. Logistics affects customer satisfaction. Customer satisfaction affects revenue. Revenue affects investment decisions. Risk behaves like a network, not a checklist. Internal auditors understand these connections because they audit end-to-end processes rather than individual departments. Every Process Has Hidden Dependencies One of the biggest challenges in modern organizations is invisible dependency. Consider a payroll process. If the HR system isn’t updated on time, payroll calculations become inaccurate. Employees receive incorrect salaries. Employee morale declines. Productivity suffers. Retention becomes more difficult. Recruitment costs increase. Again, one small delay creates consequences far beyond the original process. The same pattern exists across procurement, finance, inventory, IT, sales, and operations. Internal Controls Are Domino Stoppers Many people think internal controls exist to satisfy compliance requirements. In reality, they exist to stop dominoes. Effective controls interrupt chain reactions before they spread. Examples include: Each control is designed to prevent a small issue from becoming a business-wide problem. Technology Reduces the Domino Effect Modern organizations use technology to identify bottlenecks before they become crises. ERP systems can notify managers when approvals remain pending. Workflow automation automatically escalates delayed requests. Artificial intelligence identifies unusual process delays. Data analytics highlights recurring bottlenecks. Process mining reveals where approvals consistently slow operations. Technology cannot eliminate every risk. But it can shorten the distance between the first domino and management’s awareness. The earlier problems are detected, the easier they are to solve. Internal Auditors Think in Chains, Not Events Traditional thinking focuses on isolated events. An internal auditor thinks differently. Instead of asking: “Why was payment delayed?” They ask: This approach identifies the root cause rather than the symptom. The objective isn’t to fix today’s payment delay. It’s to ensure tomorrow’s payment delay never occurs. How to Prevent the First Domino Organizations can significantly reduce business risk by strengthening the earliest stages of every process. Some practical steps include: Design Clear Approval Workflows Every approval should have defined owners, timelines, and escalation paths. Remove Single Points of Failure No process should depend entirely on one individual. Delegate authority and establish backup approvers. Monitor Process Bottlenecks Use dashboards and analytics to identify recurring delays before they affect downstream operations. Test Business Continuity Ask, “If this process stopped today, what would happen tomorrow?” Understanding dependencies is the first step toward resilience. Focus on Prevention Don’t wait until customers complain or revenue declines. Address

The Domino Theory of Business Risk: How One Missing Approval Can Trigger a Chain Reaction of Business Failures Read More »

The Psychology of Fraud: Most Fraud Isn’t Committed Because People Are Evil. It’s Because Systems Quietly Allow It.

When a major fraud case makes headlines, the narrative is almost always the same. “A dishonest employee stole company funds.” “A finance executive manipulated financial statements.” “A procurement manager accepted kickbacks.” The story usually ends with one conclusion: The person was unethical. But what if that’s only part of the truth? What if fraud isn’t simply a problem of bad people? What if it is, more often than we would like to admit, a problem of bad systems? This is one of the most important lessons every internal auditor, risk manager, and business leader must understand. Most fraud isn’t committed because people are inherently evil. It happens because organizations quietly create environments where fraud becomes possible, justifiable, and sometimes surprisingly easy. Fraud Begins Long Before Money Disappears People often think fraud starts when money is stolen. It doesn’t. Fraud usually begins much earlier. It starts when a small control is ignored. An approval is skipped because “it’s urgent.” A password is shared because “it’s more convenient.” A reconciliation is delayed because “we’ll do it later.” An employee is given unrestricted system access because “they’ve always been trustworthy.” None of these actions seem dangerous on their own. But together, they slowly weaken the organization’s control environment. Fraud doesn’t suddenly appear. It grows in the spaces where controls quietly disappear. The Fraud Triangle: Why Good People Sometimes Make Bad Decisions One of the most influential concepts in fraud prevention is the Fraud Triangle, developed by criminologist Donald Cressey. According to this model, fraud typically occurs when three conditions exist simultaneously: An employee under financial pressure may never commit fraud if strong controls eliminate the opportunity. Likewise, abundant opportunities may not result in fraud if employees feel accountable and supported. Fraud often emerges only when all three elements align. This explains why the same person may behave honestly in one organization but unethically in another. The environment matters. Opportunity Is the Most Controllable Factor Organizations cannot eliminate every financial pressure employees face. Nor can they completely control how individuals think. But they can control opportunity. Opportunity is created when systems allow people to bypass controls without detection. Examples include: These weaknesses don’t cause fraud by themselves. They simply make fraud easier. A locked door doesn’t guarantee safety. But an unlocked door certainly increases risk. Fraud Rarely Starts Big Movies often portray fraud as dramatic schemes involving millions of dollars. Reality is usually much quieter. It often begins with something small. An employee borrows company cash intending to repay it later. A reimbursement claim includes one personal expense. A purchase order is split to avoid approval limits. A vendor invoice is processed early for a friend. Each decision becomes slightly easier than the previous one. Behavior gradually changes. Controls gradually weaken. Eventually, what started as a minor exception becomes an established pattern. Fraud grows through normalization. People Rationalize More Than They Realize One of the most fascinating aspects of fraud psychology is that many perpetrators don’t initially see themselves as criminals. Instead, they create stories that justify their actions. You may hear thoughts like: These rationalizations reduce guilt. The individual begins viewing the act as understandable rather than unethical. This is why ethical culture matters as much as written policies. Weak Systems Quietly Encourage Wrong Behavior Imagine two organizations. Organization A Organization B Which organization is more likely to experience fraud? The answer has little to do with employee personalities. It has everything to do with system design. Strong systems discourage misconduct. Weak systems silently invite it. Organizational Culture Shapes Ethical Decisions Culture influences behavior more than most organizations realize. Consider these two messages from management. Message One: “Meet the target at any cost.” Message Two: “Meet the target, but never compromise our values.” The first encourages shortcuts. The second reinforces accountability. Employees pay attention not only to policies but also to incentives. When organizations reward results without considering how those results are achieved, ethical boundaries begin to blur. Culture becomes either the strongest control—or the weakest. Internal Controls Protect Honest Employees Too Many people view internal controls as barriers. In reality, they are safeguards. Good employees benefit from strong controls because they: Internal controls don’t exist because management distrusts employees. They exist because humans are imperfect. Even well-intentioned people make poor decisions under pressure. Technology Is Changing Fraud—But Not Human Nature Modern fraud looks different from decades ago. Today, it may involve: Technology changes the methods. Human psychology remains remarkably consistent. Pressure. Opportunity. Rationalization. Understanding these drivers is just as important today as it was fifty years ago. The Role of Internal Audit The best internal auditors don’t simply search for fraud. They evaluate whether the organization unintentionally creates opportunities for fraud. Instead of asking: “Who might steal?” They ask: “Where could someone steal?” Instead of focusing solely on individuals, they examine: This shift transforms internal audit from detective to architect. Rather than investigating yesterday’s fraud, auditors help design systems that prevent tomorrow’s. Preventing Fraud Starts with Better Questions Organizations often ask: “Can we trust our employees?” A better question is: “Have we built a system that makes trust sustainable?” Trust without verification creates vulnerability. Verification without trust creates fear. Strong governance balances both. Ask questions such as: These questions reveal more than any annual fraud survey. Fraud Prevention Is a Leadership Responsibility Fraud is not solely the responsibility of internal audit. It belongs to: Every department influences the control environment. Every leader shapes organizational culture. Every process either strengthens or weakens fraud prevention. The most resilient organizations understand that fraud prevention is not an annual exercise. It is a daily habit. Final Thoughts It’s comforting to believe that fraud happens only because a few dishonest people make bad choices. The reality is more complex—and more important. Most people don’t wake up planning to commit fraud. But under enough pressure, with enough opportunity, and with enough justification, ordinary individuals can make extraordinary mistakes. That’s why organizations should spend less time asking, “Who can we trust?” and more time asking, “What kind of

The Psychology of Fraud: Most Fraud Isn’t Committed Because People Are Evil. It’s Because Systems Quietly Allow It. Read More »

Why Every Business Leaves Fingerprints: The Hidden Patterns Every Internal Auditor Should Learn to Read

When detectives investigate a crime scene, they don’t always expect to find a clear confession. Instead, they search for fingerprints. A fingerprint tells a story. It reveals who was present, where they interacted, and sometimes how an event unfolded. Businesses are no different. Every organization leaves fingerprints. Not on glass windows or door handles—but across purchase orders, approval workflows, vendor relationships, inventory movements, expense claims, emails, ERP systems, and financial transactions. To most people, these are just business records. To an experienced internal auditor, they are fingerprints waiting to be interpreted. The job of an auditor isn’t simply to verify numbers. It is to recognize the patterns that those numbers create. Businesses Don’t Hide Information—They Leave Clues One of the biggest misconceptions about fraud or operational failures is that someone successfully hides everything. In reality, very little remains hidden. People leave traces everywhere. Every approval. Every purchase. Every payment. Every inventory adjustment. Every vendor creation. Every login. Every manual journal entry. Modern businesses generate thousands of operational footprints every single day. The challenge isn’t finding data. The challenge is knowing which patterns matter. What Is a Business Fingerprint? A business fingerprint is a recurring operational pattern that reflects how an organization actually behaves. Policies describe how work should happen. Fingerprints reveal how work really happens. For example: A procurement policy may require three competitive quotations. Yet every large purchase consistently goes to the same supplier. That’s a fingerprint. A finance policy may require manager approval before payment. Yet one manager approves 90% of all urgent requests. That’s another fingerprint. Fingerprints don’t automatically indicate fraud. But they always deserve attention. Purchase Patterns Tell Stories Every purchase has a history. Not just a price. Think beyond the invoice. Ask questions such as: Individually, these transactions may appear normal. Collectively, they reveal behavior. Imagine a company where dozens of purchases are consistently valued at ₹4.95 lakh while approvals above ₹5 lakh require senior management authorization. Each purchase appears compliant. Together, they reveal a pattern of approval avoidance. The fingerprint isn’t the amount. The fingerprint is the consistency. Approval Patterns Reveal Organizational Culture Approvals are one of the richest sources of operational intelligence. Most organizations view approvals as administrative formalities. Internal auditors view them differently. Every approval answers several questions: Suppose one manager approves nearly every exception request. Why? Perhaps they’re highly trusted. Or perhaps approval authority has become concentrated in one individual. That concentration itself creates risk. Fingerprints aren’t always suspicious. Sometimes they simply reveal structural weaknesses. Vendor Patterns Expose Hidden Risks Vendor data often tells stories that financial statements never reveal. Consider these examples: Each observation may have a legitimate explanation. But together, they create a fingerprint. Experienced auditors don’t jump to conclusions. They investigate the pattern. Inventory Leaves Fingerprints Too Inventory doesn’t disappear randomly. It follows behavior. Repeated stock adjustments. Frequent write-offs. Unexpected shortages. Excess obsolete inventory. Warehouse transfers near reporting dates. None of these events exist in isolation. Inventory reflects operational discipline—or the lack of it. Like water finding the smallest crack, inventory eventually exposes weaknesses in internal controls. Financial Statements Show Results. Fingerprints Show Causes. Financial statements answer questions like: Important questions. But they don’t explain why those numbers occurred. Business fingerprints provide context. Why did procurement costs increase? Why are receivables rising? Why are inventory write-offs becoming frequent? Why are manual journal entries increasing? Numbers describe outcomes. Patterns explain behavior. That’s why internal auditors spend as much time understanding processes as they do reviewing financial reports. The Digital Age Has Created More Fingerprints Than Ever Years ago, auditors relied heavily on paper records. Today, every digital action creates a trail. Organizations leave fingerprints through: The challenge has shifted. There isn’t too little information. There is almost too much. Modern auditing is about separating meaningful signals from background noise. Patterns Matter More Than Individual Transactions One late payment rarely indicates a problem. One inventory adjustment may be perfectly legitimate. One manual journal entry isn’t unusual. But repeated exceptions create patterns. Consider these scenarios: Each individual event seems harmless. The repetition creates the fingerprint. And repetition almost always deserves investigation. Fraud Leaves Behavioral Fingerprints Contrary to popular belief, fraud rarely begins with stolen money. It begins with unusual behavior. Someone starts bypassing controls. Documentation becomes incomplete. Approvals become rushed. Role segregation weakens. Access rights expand unnecessarily. Eventually, financial loss follows. The money is often the final clue—not the first. This is why effective fraud detection focuses on behavioral patterns instead of isolated financial anomalies. Technology Is Teaching Auditors to Read Fingerprints Faster Today’s internal auditors use advanced analytics to detect operational patterns that would be impossible to identify manually. Modern tools include: Instead of reviewing hundreds of invoices, auditors can analyze millions of transactions and immediately identify unusual behavior. Technology doesn’t replace professional judgment. It enhances the auditor’s ability to recognize fingerprints hidden inside massive datasets. Why Internal Controls Shape Fingerprints Business fingerprints don’t appear by accident. They are shaped by internal controls. Strong controls create healthy patterns: Weak controls create unhealthy patterns: In other words, every control leaves its own fingerprint. The question is whether it’s the fingerprint of discipline or vulnerability. Becoming a Better Auditor Means Becoming a Better Observer Great auditors don’t see more documents than everyone else. They simply observe differently. They ask questions others overlook. Why is this purchase always urgent? Why does one vendor dominate? Why are approvals happening in seconds? Why are the same exceptions recurring? Observation is one of the most underrated audit skills. The ability to connect small details often reveals much larger risks. Final Thoughts Every business leaves fingerprints. Not because organizations are trying to hide something, but because every process, decision, approval, and transaction reflects human behavior. Most people see invoices. Auditors see purchasing habits. Most people see approval signatures. Auditors see decision-making patterns. Most people see vendors. Auditors see relationship networks. That difference is what transforms internal audit from a compliance exercise into a strategic business function. The best auditors don’t just examine documents. They read the

Why Every Business Leaves Fingerprints: The Hidden Patterns Every Internal Auditor Should Learn to Read Read More »