Internal fraud in banks is any scheme carried out by an employee, officer, or director against their own financial institution or its customers, using the legitimate access that comes with the job to bypass the controls built to stop outsiders. The Association of Certified Fraud Examiners’ 2024 global study recorded 305 fraud cases in banking and financial services with a median loss of $120,000 per incident. Perpetrators face federal prison exposure of up to 30 years, seven-figure fines, and industry bans that end a banking career permanently.
What Counts As Internal Bank Fraud
The term covers any dishonest act by someone on the inside, whether the target is the bank’s own balance sheet or a customer’s account. Fraud examiners sort these schemes into three categories.
Asset misappropriation is the theft or misuse of the bank’s resources or customer money. It is the most common category by a wide margin and runs from a teller pocketing cash to a payments clerk diverting incoming deposits. Individual amounts are often small; the schemes tend to survive because they run quietly for months or years.
Corruption means using the position for personal gain, usually through an arrangement with someone outside the bank. Bribery, kickbacks, and conflicts of interest live here. In the ACFE’s 2024 data, corruption showed up in 44% of banking fraud cases, the largest share of any scheme type in the sector.
Financial statement fraud is the deliberate misrepresentation of the bank’s financial condition through falsified numbers or omitted disclosures. It appears in only about 5% of banking cases but produces the largest dollar losses because it is almost always driven from the top of the organization.
Common Schemes Against Customer Accounts
When the insider goes after customers, the customer is the immediate victim, though the bank usually ends up absorbing the loss.
Unauthorized Transfers
An employee with system credentials can initiate wire transfers or electronic debits without the account holder’s knowledge. Accounts belonging to elderly clients and estates of deceased depositors are frequent targets because activity on them draws little scrutiny. Stolen funds usually move through several intermediary accounts before being withdrawn as cash.
Customers have a backstop under Regulation E. Report an unauthorized electronic transfer within two business days of discovering it and your liability is capped at $50. Report within 60 days of receiving the statement and the cap rises to $500. Miss the 60-day window and you can be liable for the full amount of transfers that happen after the deadline.
Lapping
Lapping is a slow-drain scheme built on the volume of daily payments. An employee handling incoming payments steals one customer’s deposit, then applies the next customer’s payment to the first account to plug the hole. Each new payment covers the previous shortfall. In one documented case, a bank employee processing mortgage payments diverted more than $195,000 over two years before the pattern broke down.
Identity Theft
Tellers, loan processors, and other staff with file access can lift Social Security numbers, dates of birth, and other personal data and either sell it or use it to open new credit in the customer’s name. Every state, the District of Columbia, Puerto Rico, and the U.S. Virgin Islands require the bank to notify affected customers when their data is compromised.
Fee Manipulation
A loan officer or account manager improperly waives fees, penalties, or interest in exchange for a personal payment from the customer who benefits. The individual amounts stay small enough to slip past audit thresholds, and the scheme tends to escalate the longer it goes undetected.
Common Schemes Against the Bank Itself
When the institution is the primary victim, the loss hits the balance sheet directly. These schemes typically require someone with authority to approve transactions or touch internal records.
Loan Fraud
A loan officer or credit analyst approves financing for unqualified borrowers in exchange for a bribe or a hidden stake in the deal. Appraisals get inflated, income documents get fabricated, underwriting standards get overridden. When the loan defaults, the bank absorbs the full principal loss. Per-incident losses on internal loan fraud tend to be among the highest of any scheme.
Ghost Employees
A payroll or HR employee with system access creates fictitious employee profiles and routes the salaries to accounts they control, or keeps a terminated worker’s profile active and redirects the direct deposit. Without cross-checks between HR records and payroll disbursements, phantom payments can continue indefinitely.
Expense Reimbursement Fraud
Administrative and executive employees submit fabricated invoices, altered receipts, or personal travel disguised as business trips. The scheme thrives where approvals are routine and the reviewing manager has no visibility into what the expenses ought to look like.
Check Kiting
Kiting exploits float, the delay between when a check is deposited and when funds actually move between banks. The perpetrator deposits a check drawn on insufficient funds at Bank A into an account at Bank B, then writes checks against the inflated balance before Bank A flags the shortfall. An employee with detailed knowledge of processing timelines can run this more effectively than an outsider, and losses grow rapidly the longer the scheme continues.
False Book Entries
Manipulating the bank’s own records is a distinct federal offense. False entries can hide losses in off-balance-sheet accounts, backdate transactions to escape audit windows, or fabricate account balances outright. This is the backbone charge for schemes that do not fit cleanly under embezzlement or wire fraud.
Federal Criminal Penalties
Three statutes cover the vast majority of internal bank fraud prosecutions, and they routinely stack against the same defendant.
- Bank fraud under 18 U.S.C. § 1344: executing or attempting a scheme to defraud a financial institution carries up to a $1 million fine and 30 years in prison. This is the broadest charge and reaches check kiting, loan fraud, and account manipulation.
- Embezzlement by a bank officer or employee under 18 U.S.C. § 656: an officer, director, agent, or employee of a federally connected bank who embezzles or willfully misapplies bank funds faces the same $1 million and 30-year maximum when the amount exceeds $1,000. Below that threshold the maximum drops to one year.
- False bank entries under 18 U.S.C. § 1005: making a false entry in the bank’s books, reports, or statements with intent to defraud carries up to $1 million and 30 years.
An employee who embezzles funds and then falsifies records to cover the theft can face separate counts under § 656 and § 1005, and prosecutors regularly pursue multiple counts to increase sentencing leverage.
Regulatory Consequences
Criminal prosecution runs alongside a separate regulatory track that can end a career on its own.
Suspicious Activity Reports With No Dollar Threshold
When a bank detects suspected criminal activity by one of its own directors, officers, or employees, it must file a Suspicious Activity Report regardless of the dollar amount involved. For external fraud, SAR filing is triggered only when the suspicious transaction exceeds $5,000. For insider abuse there is no minimum. The rule requires a filing whenever the bank has a substantial basis for identifying an institution-affiliated party as having committed or aided a criminal violation.
Prohibition Orders and Other Enforcement Tools
The Office of the Comptroller of the Currency and other banking regulators can impose consequences that effectively end a person’s career in financial services. The most severe is a prohibition order under 12 U.S.C. § 1818(e), which bars the individual from participating in any capacity in the affairs of any insured depository institution. That means no work at, no board seat on, and no control over any bank in the country.
Regulators can also impose civil money penalties, cease-and-desist orders requiring the individual to stop specific conduct, and restitution orders requiring repayment. For employees convicted of or charged with certain crimes, federal law triggers an automatic prohibition without any separate regulatory proceeding.
How Banks Try to Stop It
No control system eliminates internal fraud, but the right combination of practices makes schemes harder to start and easier to catch. The organizing principle is that no single employee should have unchecked authority over any complete transaction cycle.
Separation of Duties and Dual Control
Separation of duties splits key functions so the person who initiates a transaction is not the same person who approves or records it. The Federal Reserve Bank of Minneapolis identifies three areas that should always be separated: custody of assets such as cash, authorization or approval of transactions, and recording or reporting those transactions. For high-risk activities like wire transfers, dual control requires two employees to act together before the transaction can proceed. When a bank is too small to fully separate these roles, compensating controls, such as spot-checks by a second employee, periodic rotation of assignments, or targeted audits, fill the gap.
Mandatory Two-Week Vacation
The FDIC has endorsed a minimum two-consecutive-week mandatory vacation policy since 1995. Most embezzlement schemes of any significant size need the perpetrator’s constant presence to manipulate records and intercept inquiries. Forcing an uninterrupted absence gives a substitute employee time to notice irregularities. FDIC examination guidance recommends removing system access during the vacation so the employee cannot work remotely to keep the scheme running.
Fidelity Bonds
Banks carry fidelity bonds, sometimes called banker’s blanket bonds, that cover losses from employee dishonesty. The fidelity clause responds when an officer or employee acts with clear intent to cause a loss and obtain a financial benefit. Coverage on a specific employee automatically cancels as soon as the bank learns of any dishonest act by that person. The Federal Deposit Insurance Act gives the FDIC authority to require a bank to obtain this coverage and, in rare cases, to purchase it on the bank’s behalf and add the cost to the institution’s deposit insurance assessment.
Protections for Employees Who Report It
Internal fraud thrives on silence, and federal law tries to break that silence with concrete anti-retaliation rules. Under the Dodd-Frank Act’s whistleblower provisions, no employer may fire, demote, suspend, threaten, or otherwise discriminate against an employee for reporting potential securities violations to the SEC. An employee who faces retaliation can recover reinstatement, double back pay with interest, and attorneys’ fees. The right to bring a retaliation claim cannot be waived by any employment agreement or forced-arbitration clause.
The statute of limitations for a retaliation claim is six years from the date the violation occurred, or three years from the date the employee reasonably should have known about the retaliation, with an absolute outer limit of ten years.