{
  "question_id": "CG-MCE-119",
  "slug": "how-to-tell-from-your-books-whether-someone-is-stealing-from-the-business",
  "display_title": "How would I tell from my books whether an employee or bookkeeper is stealing from the business?",
  "format": "article-v2",
  "applies_to": {
    "countries": [
      "US"
    ],
    "frameworks": [],
    "tax_year": null,
    "platforms": []
  },
  "general_concept": true,
  "summary": "If the person you suspect keeps the books, the books cannot settle it: theft can come with false or altered records. Start with records that person does not control: bank statements and check images, card statements, IRS tax-deposit history, and payroll and vendor records you obtain directly. A mismatch is a question until outside records confirm a pattern. Preserve records before anything visible happens, check any crime policy's notice terms, and involve a forensic accountant and a lawyer before acting.",
  "body": "## Why can't the books settle it when the person you suspect keeps them?\n\nAS 2401, the PCAOB's standard on fraud in audits of public companies, says misappropriation of assets may be accompanied by false or misleading records or documents, possibly created by circumventing controls, and that fraud may be concealed by withholding evidence, misrepresenting information in response to inquiries or falsifying documentation. Someone who records the transactions, reconciles the bank and answers your questions controls all three routes. A tidy file, a balanced reconciliation and a ready explanation therefore tell you little either way: the file shows what was recorded, not what happened.\n\nAS 1105, the same body's audit-evidence standard, gives the principle to work from: evidence from a knowledgeable source independent of the company is more reliable than evidence obtained only from internal company sources. So begin with what a bank, card issuer, payroll provider, the IRS, vendors or customers hold, and compare the books with it.\n\nIf the person handles cash, stock or payments but cannot change the records, the file is more useful: a gap between it and the bank or the stockroom points at what they handled. If they keep the books, treat the file as their account of events and rest every conclusion on an outside record.\n\n## How does money leave a small business through its own records?\n\nAS 2401 says misappropriation can be accomplished in various ways, including embezzling receipts, stealing assets, or causing an entity to pay for goods or services that have not been received. The Association of Certified Fraud Examiners (ACFE), in its key findings from the 2026 Report to the Nations, names billing schemes, theft of noncash assets, and check and payment tampering among the most significant fraud risks. In a small business those routes take six forms:\n\n- **Invented or altered payees.** The business pays a vendor that does not exist, or a genuine payment is altered or redirected.\n- **Diverted receipts.** Customer money is taken before or after it is recorded, and the customer's balance is cleared with credits or write-offs.\n- **Manipulated payroll.** Hours or pay rates are overstated; pay can also go to people who do no work.\n- **Personal spending booked as business expense.** A business card or account pays for personal purchases, coded to ordinary expense accounts.\n- **Adjustments that hide the rest.** AS 2401 lists lack of timely and appropriate documentation of transactions, such as credits for merchandise returns, among conditions that create opportunity. Journal entries, voids, write-offs and reconciliation adjustments can hide a loss.\n- **Removal of stock or assets.** Inventory, equipment or other property leaves, and the records are adjusted or never kept.\n\n## What record shows each one, and where do you get it?\n\nThis examination list pairs each mechanism with its record, independent source and pattern:\n\n| Mechanism | Record to obtain | Independent source | Pattern to look for |\n|---|---|---|---|\n| Invented or altered payees | Cleared check images, front and back; the vendor's statement of account, requested by you | Your bank, under your own login; the vendor | A payee or endorsement on the bank's image that differs from the check register; payees you do not recognise; payments the books and bank show as made to a vendor that the vendor's statement shows as unpaid |\n| Diverted receipts | Deposit detail and deposit-slip images; statements of account confirmed with customers | Your bank; your customers | Deposits smaller or later than the receipts the books record as received (customer payments and cash sales); a customer who paid an invoice the books show as open, credited or written off |\n| Manipulated payroll | Federal tax deposit history; payroll debits on the bank statement; the provider's pay-run records | EFTPS under your own PIN; your bank; your payroll provider, as its own documentation allows, not a report the bookkeeper exports | Names you do not employ; hours or rates you did not approve; net-pay debits above the payroll you expect; tax deposits missing or smaller than payroll reports show |\n| Personal spending | Card statements and the list of cards on the account; the business bank statement | The card issuer, under the account owner's login; your bank, under your own login | Card or bank payments to merchants, billers or card accounts with no business purpose; cards you did not know existed; personal charges coded to business expense accounts; reimbursements to the person with no approved claim behind them |\n| Adjustments that hide the rest | Reconciliation reports and the file's change history | A specialist's copy of the file; your own bank records | Reconciliation adjustments; missing or redone reconciliation reports; credits, voids or write-offs clustered on one login or period |\n| Stock or assets | Vendor statements of purchases; a physical count; the fixed-asset list | Your vendors; a count by someone other than the suspect | Purchases that sales and stock on hand do not explain; listed assets you cannot find |\n\nReceipts taken before they are recorded leave no entry to compare; they surface only in records that capture the sale outside the file, or through the specialist's work, so a clean deposit comparison does not clear them.\n\n## Which records can you get without going through the bookkeeper?\n\nUse these sources first:\n\n- **Your bank.** Wells Fargo's page \"Manage Accounts with Wells Fargo Business Online\" (undated) says users can view past transactions for a limited period, access images of their checks, confirm deposit details and get electronic statements for any eligible business account. Its \"Deposit Details\" page (undated) says users can view the front and back of business check images and view, print and save images of deposit slips. Use a login that is yours alone, and save copies now.\n- **Your card issuer.** American Express's Employee Cards help page, dated January 24, 2025, says you can view all your Employee Cards in one place, and that a trusted team member made an Account Manager with Full Access can add and manage Employee Cards, set spending limits and track the amount each employee spends. If the person you suspect holds that role, they manage the cards.\n\n  The bank and card features described here are Wells Fargo's, Chase's and American Express's; your own bank's or card issuer's documentation sets out what it offers and how to request it.\n- **The IRS.** The IRS page \"Outsourcing payroll duties\" says the employer is ultimately responsible for the deposit and payment of federal tax liabilities, and that employers should register on EFTPS to get their own PIN and use it to periodically verify payments.\n\n  The IRS's EFTPS page lists viewing 15 months of payment history among its functions (the IRS outsourcing page says 16) and says new enrollments can take up to five business days to process. The same page says individual taxpayers can no longer create new accounts and current users can still use EFTPS \"for now\"; check it before enrolling. If the person opens the business's post, ask your advisers before enrolling.\n- **Your payroll provider.** Its own documentation governs which pay-run records you can obtain directly and how; a report the bookkeeper exports for you is not independent.\n- **Vendors and customers.** A statement of account you request yourself shows what was billed and paid. AS 2401 says collusion with third parties can make false evidence appear persuasive, so a statement from a vendor the person introduced, or one you do not otherwise deal with, is not independent. If the bookkeeper is their usual contact, the request may reach that person, so time it with your advisers.\n\n## What change history and access records matter, and can looking at them alert the person?\n\nIntuit's help page \"View details for missing reconciliation reports or reconciled transactions in QuickBooks Online\" (updated 8/24/2026) says you can find out who made changes to reconciliation reports or transactions from the Audit Log, and that a transaction's Audit History displays all changes, most recent first, including who made each change. The same page lists three possible causes of a missing reconciliation report: an Accountant user ran Undo Reconcile, the Primary Admin unreconciled a transaction or undid an entire reconciliation, or the account was merged with another account. A missing report is a question, not a finding.\n\nA change history shows which login did what and when, not whether an entry was true or who used a shared login. How long it is kept, and whether it can be switched off, differ by product: check your vendor's documentation and the guide on using the audit trail.\n\nIntuit's \"User roles and access rights\" page (updated 9/8/2026) says whoever first sets up a QuickBooks Online account is assigned the primary admin role, and that only admins can add, edit or remove admins; if the bookkeeper set up the file, they may hold that role. Wells Fargo's Manage Accounts page says you can review who has been added to your account, whether an employee, a bookkeeper or an accountant. Chase's help page \"Access & Security Manager: View activity\" (undated) describes keeping track of how authorized users are helping manage the account. Capture those lists and logs as they stand.\n\nLooking can itself be seen. Signing in to the accounting file, adding a user or changing a setting may be recorded in the history the person reads daily, and a bank administrator may see other users' activity. Unless your platform's documentation says otherwise, treat opening the file as a visible step and leave it to the specialist in the sequence below.\n\n## When is an odd transaction a finding, and when is it only a question?\n\nAS 2401 separates warning signs from conclusions. After examples such as a missing contract or a subsidiary ledger that does not reconcile to its control account, it says these conditions may be the result of circumstances other than fraud: documents may legitimately have been lost or misfiled, and a ledger may be out of balance because of an unintentional accounting error. The same standard says fraud is a broad legal concept and auditors do not make legal determinations of whether fraud has occurred. An owner is in no better position to make one.\n\n| What you have | What it is |\n|---|---|\n| One unexplained payment, deposit gap or adjustment | An indicator, consistent with error, timing or a legitimate change |\n| A plausible explanation from the person you suspect | A claim to test against outside records, not clearance |\n| The same pattern over several months, confirmed item by item in bank, card, payroll or IRS records | A corroborated pattern for your professionals to assess, still not a conclusion about any person |\n| A pattern tied to one login | Evidence about that login, until shared or borrowed credentials are ruled out |\n\nTest the ordinary explanations before treating anyone as responsible:\n\n- **Timing.** A check recorded in one month clears in the next, a deposit straddles month-end, or customers are paying on credit terms.\n- **Posting errors.** The right amount went to the wrong account, vendor or customer, or was entered twice.\n- **Legitimate changes.** A new vendor, an approved raise, a credit you agreed to, an account merged into another, or a bank fee explains it.\n- **Other people.** Another staff member, a shared login or an outside party could account for it.\n\nTesting means tracing each item to the outside record and to its supporting document and approval, not to anyone's account of it.\n\n## What should be preserved, and in what order, before anything visible happens?\n\nThe ACFE article \"You Discovered Fraud — Now What?\" (November 2017) puts preservation of evidence first, advises avoiding the temptation to examine the evidence on your own, and notes that simply turning a computer off or on can alter potential evidence. This preservation and sequencing list keeps that order:\n\n1. **Note what you have seen.** Record dates, amounts, which record each came from and who else knows, and keep the note off the business's shared systems.\n2. **Save the independent records quietly.** Download statements, check and deposit images, card statements, EFTPS history and the bank's and card issuer's user lists for the whole period, using logins that are yours alone, and only where doing so is not visible. Online history covers a limited window (EFTPS 15 months; Wells Fargo up to 18 months of transactions); earlier periods are for your professionals to obtain.\n3. **Read your crime or employee-dishonesty policy, if you have one.** Its duties may already be running, so do not let the next step delay its notice.\n4. **Engage a lawyer and a forensic accountant or fraud examiner.** They plan everything after this point.\n5. **Give the insurer notice as the policy requires.** Do not wait for the review to finish.\n6. **Have a specialist capture the accounting file, its change history, email and devices.** Nothing is switched off, wiped, reassigned or reset first.\n7. **Then change access, duties or controls, on advice.** Removing access or locking the person out earlier is the signal most likely to prompt alteration; removing a departing person's access is a separate question. If money is still leaving, your advisers may bring some of these measures forward, before the specialist's capture; the order in this list yields to their advice.\n\nIf step 2 cannot be done unseen, for example because statements reach only the person's inbox or you have no login of your own, skip it: go to steps 3 and 4, and let the professionals obtain the records.\n\n## How can you limit further loss without signalling suspicion?\n\nMeasures that stop loss outright are visible. American Express's Employee Cards page says you can freeze and unfreeze Employee Cards at any time in your online account. A frozen card fails when the holder next uses it, so the freeze is noticed; removing a login, changing a password or tightening approvals is noticed the same way. Keep those for step 7; designing checks and permissions is a separate question. If money is still leaving, your advisers may bring some of these measures forward, before the specialist's capture; the order in the preservation list yields to their advice.\n\nBesides checking EFTPS under your own PIN, what you can usually do quietly is watch:\n\n- **Bank alerts.** Wells Fargo's Manage Accounts page describes alerts that send updates on balances, account activity or upcoming payments.\n- **Card alerts.** American Express's Employee Cards page says you receive real-time alerts, and that you will not receive an alert if an employee makes a purchase at a merchant from an approved category.\n\nBefore switching on an alert, check whether the platform shows it to other administrators. If money is still leaving, tell your advisers at once: under the specimen crime form below, cover for an employee can end once a partner or manager knows of a dishonest act above a set amount, so later losses by that person may not be covered.\n\n## When does the review pass to an accountant, a fraud examiner, the insurer or a lawyer?\n\nBring the professionals in at step 4 above, as soon as the independent records are saved, without waiting to corroborate a pattern yourself; if saving them would be visible, the person is the only one who understands the books, or your policy's discovery definition is met, bring them in straight away. Each role differs:\n\n- **Your regular accountant.** The AICPA's illustrative engagement letter for an engagement to prepare financial statements, in AR-C section 70, tells the client the engagement cannot be relied upon to identify or disclose misstatements, including those caused by fraud or error, and lists the prevention and detection of fraud among the client's responsibilities. A routine engagement is not an investigation; ask for one that is, or for a referral. The \"Now What?\" article warns that someone on the accounting team may be part of the problem: if your regular accountant is the firm you suspect, or works closely with the person, do not raise it with them; go straight to an independent forensic accountant or CFE.\n- **A forensic accountant or Certified Fraud Examiner.** The ACFE's CFE Credential page (undated) describes CFEs as trained professionals with skills in preventing, detecting and investigating fraud. The ACFE's \"Now What?\" article advises enlisting a forensic accountant and a computer forensic specialist to collect, analyze and store the data.\n- **A lawyer.** The \"Now What?\" article advises retaining an employment lawyer to stay on the right side of the law. Raising the matter with the person, any decision about their job, any demand for repayment and any report to authorities are for counsel's advice, not this review.\n\nActing alone can damage both recovery and the business's position: an early step toward the person ends quiet record-gathering, a private repayment deal can collide with an insurer's recovery rights, and an accusation resting on an error harms an innocent person and exposes the business.\n\n## What does a crime or employee-dishonesty policy expect once you suspect theft?\n\nYour own policy's wording governs, so read it now. Travelers publishes a specimen crime policy form, CRI-3001 (edition 01-09), that shows what a policy of this class can contain:\n\n- **Discovery.** It is the moment the insured, a partner or a management staff member first becomes aware of facts that would cause a reasonable person to assume a covered loss has been or will be incurred, whenever the acts occurred and even though the details of loss may not then be known, or first receives notice of a claim alleging such a loss, whichever comes first. That can be before you have proof.\n- **Duties.** After discovering a loss, or a situation that may result in one, exceeding 25% of the single loss retention, the insured has five duties:\n  - Notify the insurer as soon as possible.\n  - Notify law enforcement if it has reason to believe a loss involves a violation of law, except for loss under insuring agreements the form lists, which include its Employee Theft agreement; any decision about a report is for your lawyer.\n  - Submit to examination under oath at the insurer's request and give a signed statement of its answers.\n  - Give a detailed, sworn proof of loss within 120 days.\n  - Cooperate in the investigation and settlement of any claim.\n- **Who counts.** Its definition of Employee excludes agents, brokers, independent contractors and others of the same general character that the definition does not otherwise include. Whether the policy responds to theft by an outside firm is for the insurer and your lawyer; doubt about cover is not a reason to delay notice.\n- **When cover for that person ends.** The policy terminates as to an employee as soon as a partner, management staff member or supervisor not in collusion becomes aware of a dishonest or fraudulent employment-related act involving more than $10,000, or 60 days after becoming aware of a non-employment-related act of that size, whether committed during or before employment.\n- **Recovery rights.** The insured must transfer to the insurer its rights of recovery for any loss the insurer has paid or settled, do everything necessary to secure those rights and do nothing after loss to impair them.\n- **Stock losses.** Loss proved solely by an inventory computation, a physical count or a profit and loss computation is excluded; once a covered loss is established wholly apart from those, inventory records and a count may support it.\n\nIf no policy of this class is in force, there is no insurer to notify, and your lawyer can advise what routes to recovery remain.\n\n## What changes if it is an outside firm, the only person who understands the books, or payroll?\n\n**An outside bookkeeping firm.** The file may sit on the firm's subscription or with the firm as primary admin, so you may not control it; getting it back is a separate question. Your bank, card and IRS records are unaffected, so the review still starts there. If your regular accountant is the firm you suspect, or works closely with the person, do not raise it with them; go straight to an independent forensic accountant or CFE. Whether your crime policy responds to theft by an outside firm is for the insurer and your lawyer; doubt about cover is not a reason to delay notice.\n\n**The only person who understands the books.** Engage an outside accountant to read the records before you change that person's duties or access. You cannot interpret the file alone, and pausing their work is itself a signal.\n\n**A loss through payroll.** Payroll is one of the few areas you can check without the person's help. Compare the provider's pay runs, obtained as its own documentation allows rather than from the bookkeeper, with the payroll debits on your bank statement, the deposits in EFTPS and the people you actually employ at the rates you approved. If the person runs payroll inside the books they keep, the pay-run records are theirs; compare instead the bank's payroll debits and EFTPS deposits with the people you employ and the rates you approved.",
  "sources": [
    {
      "id": "REF::1",
      "url": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS2401",
      "title": "AS 2401: Consideration of Fraud in a Financial Statement Audit",
      "publisher": "Public Company Accounting Oversight Board",
      "published": "undated web edition",
      "retrieved_at": "2026-09-28T12:42:18+00:00",
      "sha256": "d2057782365bf409ce720e1d308378db4fb3d079220991dac6f999a99b21b7b4",
      "supports": [
        "C1",
        "C2",
        "C4",
        "C8",
        "C27",
        "C28",
        "C29",
        "C30",
        "C31",
        "C67",
        "C68",
        "C69"
      ]
    },
    {
      "id": "REF::2",
      "url": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105",
      "title": "AS 1105: Audit Evidence",
      "publisher": "Public Company Accounting Oversight Board",
      "published": "undated web edition",
      "retrieved_at": "2026-09-28T12:42:19+00:00",
      "sha256": "cdccfb204dfd50da5b98a6ca3f597dfebc6ba3099cbe5b58ffbde32275c4806b",
      "supports": [
        "C3"
      ]
    },
    {
      "id": "REF::3",
      "url": "https://www.acfe.com/acfe-insights-blog/blog-detail?s=key-findings-report-to-the-nations-2026",
      "title": "Key Findings from Occupational Fraud 2026: A Report to the Nations",
      "publisher": "Association of Certified Fraud Examiners",
      "published": "May 2026",
      "retrieved_at": "2026-09-28T12:42:19+00:00",
      "sha256": "627c89ad017346f5c9abf1d0e08b7862b80b3b9149de27b2033a609ea253ee07",
      "supports": [
        "C5"
      ]
    },
    {
      "id": "REF::4",
      "url": "https://www.acfe.com/acfe-insights-blog/blog-detail?s=overtime-payroll-fraud",
      "title": "Overtime: The Fraud That Does Not Pay",
      "publisher": "Association of Certified Fraud Examiners",
      "published": "January 2026",
      "retrieved_at": "2026-09-28T12:42:20+00:00",
      "sha256": "dcefbb45cbc50823557cc0972f5ecc28f49aaefb58dd34cd76cbf522c78a3cad",
      "supports": [
        "C6"
      ]
    },
    {
      "id": "REF::5",
      "url": "https://www.acfe.com/acfe-insights-blog/blog-detail?s=you-discovered-fraud-now-what",
      "title": "You Discovered Fraud — Now What? 5 Steps to Take After Suspecting Fraud in Your Company",
      "publisher": "Association of Certified Fraud Examiners",
      "published": "November 2017",
      "retrieved_at": "2026-09-28T12:42:21+00:00",
      "sha256": "80eb2a5dcb15ca6b5e81afebf91f983cca8536bf753c7a0db9e5bf6ca29cc2b8",
      "supports": [
        "C32",
        "C33",
        "C34",
        "C42",
        "C43",
        "C77",
        "C78",
        "C79"
      ]
    },
    {
      "id": "REF::6",
      "url": "https://www.acfe.com/cfe-credential",
      "title": "CFE Credential",
      "publisher": "Association of Certified Fraud Examiners",
      "published": "undated",
      "retrieved_at": "2026-09-28T12:42:22+00:00",
      "sha256": "0cbdb5f664b2aba266c4aed3cad399a9dcd8ef611e342e108e52138855bfe2a9",
      "supports": [
        "C41"
      ]
    },
    {
      "id": "REF::7",
      "url": "https://assets.ctfassets.net/rb9cdnjh59cm/30H0g7T5e1Rbd00RW9YJxE/1ce170fe7ac2edafe31f0039c2e2fba4/ps-ar-c-sections.pdf",
      "title": "Accounting and Review Services (Clarified) [AR-C]",
      "publisher": "American Institute of CPAs",
      "published": "copyright 2026",
      "retrieved_at": "2026-09-28T12:42:22+00:00",
      "sha256": "afcea964575cda8135530afe5176a9f0a01df5b8bf4c642d7c8c0f94598ca2d5",
      "supports": [
        "C38",
        "C39",
        "C40"
      ]
    },
    {
      "id": "REF::8",
      "url": "https://www.irs.gov/businesses/small-businesses-self-employed/outsourcing-payroll-duties",
      "title": "Outsourcing payroll duties",
      "publisher": "Internal Revenue Service",
      "published": "last reviewed or updated 04-Mar-2026",
      "retrieved_at": "2026-09-28T12:42:24+00:00",
      "sha256": "10ad3011c13d853716850a6a18a4da69fb7a898dc4a59c0ae308641dbbe1506c",
      "supports": [
        "C16",
        "C17",
        "C70"
      ]
    },
    {
      "id": "REF::9",
      "url": "https://www.irs.gov/payments/eftps-the-electronic-federal-tax-payment-system",
      "title": "EFTPS: The Electronic Federal Tax Payment System",
      "publisher": "Internal Revenue Service",
      "published": "last reviewed or updated 28-Jun-2026",
      "retrieved_at": "2026-09-28T12:42:24+00:00",
      "sha256": "616145e11a9f1eba4b156168ae32900ee1304ed414f3e894b25949fd0e9f5b8b",
      "supports": [
        "C18",
        "C19",
        "C71",
        "C72",
        "C73"
      ]
    },
    {
      "id": "REF::10",
      "url": "https://www.wellsfargo.com/biz/online-banking/manage-accounts/",
      "title": "Manage Accounts with Wells Fargo Business Online",
      "publisher": "Wells Fargo",
      "published": "undated",
      "retrieved_at": "2026-09-28T12:42:25+00:00",
      "sha256": "8f38bc2ae4e2c82fbfb3773e4e9890e347b8fe7ba91e1bf8f6b013b24f78c513",
      "supports": [
        "C9",
        "C10",
        "C25",
        "C36",
        "C74"
      ]
    },
    {
      "id": "REF::11",
      "url": "https://www.wellsfargo.com/biz/online-banking/deposit-details/",
      "title": "Account Activity - Deposit Details - Wells Fargo Business Online",
      "publisher": "Wells Fargo",
      "published": "undated",
      "retrieved_at": "2026-09-28T12:42:25+00:00",
      "sha256": "30c66b3c2bb4499075d01e3e09fae86fc6ef3ecf95c45b6b8080459ec0a9ab04",
      "supports": [
        "C11",
        "C12"
      ]
    },
    {
      "id": "REF::12",
      "url": "https://www.chase.com/digital/customer-service/helpful-tips/business-banking/security/view-activity",
      "title": "Access & Security Manager: View Activity",
      "publisher": "JPMorgan Chase Bank",
      "published": "undated",
      "retrieved_at": "2026-09-28T12:42:26+00:00",
      "sha256": "895c9525286df4315732f4ac83f5438c6094507688a03ef624f994e923b21754",
      "supports": [
        "C26"
      ]
    },
    {
      "id": "REF::13",
      "url": "https://www.americanexpress.com/en-us/business/blueprint/help-center/business-card/employee-cards/",
      "title": "Employee Cards",
      "publisher": "American Express",
      "published": "January 24, 2025",
      "retrieved_at": "2026-09-28T12:42:26+00:00",
      "sha256": "ffff2716b7311e6ed6979573badd35d85453f73e7d8755ca8632ca8485ad4c86",
      "supports": [
        "C13",
        "C14",
        "C15",
        "C35",
        "C37",
        "C65",
        "C66"
      ]
    },
    {
      "id": "REF::14",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/statement-reconciliation/view-details-missing-reconciliation-reports/L2C82hF5l_US_en_US",
      "title": "View details for missing reconciliation reports or reconciled transactions in QuickBooks Online",
      "publisher": "Intuit",
      "published": "last updated 8/24/2026",
      "retrieved_at": "2026-09-28T12:44:09+00:00",
      "sha256": "c9a724fcf002086a7df642e285708de13b76f7d599157430ca52ccaa5cd16b08",
      "supports": [
        "C20",
        "C21",
        "C22",
        "C75",
        "C76"
      ]
    },
    {
      "id": "REF::15",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/user-roles-access-rights-quickbooks-online/L66POfRrI_US_en_US",
      "title": "User roles and access rights",
      "publisher": "Intuit",
      "published": "last updated 9/8/2026",
      "retrieved_at": "2026-09-28T12:46:31+00:00",
      "sha256": "2b880966b88e8841fe81fbba40b4f45207dd59ee3bf5e6f3a544ad8e90155cdb",
      "supports": [
        "C23",
        "C24"
      ]
    },
    {
      "id": "REF::16",
      "url": "https://asset.trvstatic.com/download/assets/cri-3001.pdf/98f30f1063c911eeb2f1deb19c93b21f",
      "title": "Crime Terms and Conditions (specimen form CRI-3001)",
      "publisher": "The Travelers Companies",
      "published": "Ed. 01-09",
      "retrieved_at": "2026-09-28T12:46:54+00:00",
      "sha256": "35eeaba9526964d1ba3e95122913bdcc844f108852f49f90d00c5213e3344259",
      "supports": [
        "C44",
        "C45",
        "C46",
        "C47",
        "C48",
        "C49",
        "C50",
        "C51",
        "C52",
        "C53",
        "C54",
        "C55",
        "C56",
        "C57",
        "C58",
        "C59",
        "C60",
        "C61",
        "C62",
        "C63",
        "C64",
        "C80"
      ]
    }
  ],
  "related": [
    {
      "question_id": "CG-MCE-023",
      "slug": "what-checks-can-a-very-small-business-put-in-place-when-the-same-person-records",
      "display_title": "What checks can a very small business put in place when the same person records, pays and reconciles?"
    },
    {
      "question_id": "CG-MCE-022",
      "slug": "how-do-i-set-up-users-and-permissions-in-my-accounting-file-so-people-only-see",
      "display_title": "How do I set up users and permissions in my accounting file so people only see and change what they should?"
    },
    {
      "question_id": "CG-MCE-120",
      "slug": "how-to-remove-a-departing-bookkeeper-or-employees-access-to-your-books",
      "display_title": "A bookkeeper or employee is leaving — how do I remove their access to my books and financial accounts, and what else do I need to change?"
    },
    {
      "question_id": "CG-P1B-FULL-037",
      "slug": "how-to-find-deleted-or-changed-transactions-in-the-audit-log",
      "display_title": "How do I use the audit trail or change log in my accounting software to find transactions that were deleted or altered?"
    }
  ],
  "review_class": "consequential",
  "review_class_trigger": "pre_publication_professional_review_required",
  "provenance": {
    "author_model": "claude-opus-5-5",
    "reviewer_model": "claude-opus-5-5",
    "review_verdict": "ACCEPT",
    "review_source": "closure",
    "review_verdict_on_sha256": "d0350a705a8e9e3e5b64ca2b6fea53db725b9cb6c756e20a161314c7f6e2c996",
    "editorial_disposition": "ACCEPT",
    "corrections": 1,
    "approved_by": null,
    "approved_at": null,
    "article_sha256": "d0350a705a8e9e3e5b64ca2b6fea53db725b9cb6c756e20a161314c7f6e2c996",
    "source_map_sha256": "d8b762df2392bd2c1b23af3ff56993b5db2627a8dd06239b1fde527c8edc7a7a",
    "transform_sha256": "2f41ae8c5f3e9443e20be9ba47b9bf5f3f30f3a49ada078b4e640ee761205e1c"
  },
  "offer": "ask",
  "offer_id": null,
  "sample_target_id": null,
  "datePublished": "2026-09-28T18:39:45Z",
  "reviewed_at": "2026-09-28T18:39:45Z",
  "content_sha": "ac78364402523a6e970ea18fafc0065eb62dda1e5f5daa37432ff4c7af14b529",
  "release": "2.12.0",
  "slug_provenance": "minted at first publication",
  "question_text": "How would I tell from my books whether an employee or bookkeeper is stealing from the business?",
  "jsonld_types": [
    "Article"
  ],
  "related_question_ids": [
    "CG-MCE-023",
    "CG-MCE-022",
    "CG-MCE-120",
    "CG-MCE-118",
    "CG-P1B-FULL-037",
    "CG-MCE-124"
  ],
  "aliases": [],
  "alias_provenance": [],
  "notice": "This guide is general information, not tax or legal advice. Confirm with a qualified professional before acting."
}
