A cargo trailer manufacturer in Tifton, Georgia, built a business with a workforce of up to 249 people, a manufacturing plant in nearby Willacoochee, and its own small motor carrier operation. Then, in 2024, it discovered something painful: a former employee had allegedly been stealing from the company. By July 2026, that discovery — and the "significant financial disruption" it caused — had become a factor in the company's Chapter 11 bankruptcy filing, with assets and liabilities each estimated in the $1 million to $10 million range.
The company wasn't undercapitalized. It wasn't a fly-by-night operation. It had real revenue, real customers, and a real factory floor. What it apparently didn't have — at least not enough of — was a system that would have caught the theft while it was still small enough to absorb.
That gap is far more common than most owners want to believe, and it's worth understanding exactly how it happens, because the fix is neither expensive nor complicated.
Small Businesses Are the Most Common Target, Not the Exception
There's a persistent myth that fraud is a big-company problem — the kind of thing that happens at organizations with sprawling accounting departments and too many hands in the till to keep track of. The data says the opposite. Businesses with fewer than 100 employees experience a median fraud loss of $141,000 per case, according to the Association of Certified Fraud Examiners' Report to the Nations — a number that rivals the median loss at organizations with 10,000 or more employees. Small companies simply don't have the scale to absorb a six-figure hit the way a large enterprise can.
The reason isn't that small business owners are careless. It's structural. A 20-person company typically has one person — sometimes the owner, sometimes a single trusted bookkeeper — handling most or all of the financial workflow: writing checks, reconciling the bank account, approving expenses, and recording the books. In a large organization, those functions are split across different people almost by default, simply because there are enough employees to divide the work. In a small business, one person often does all of it, and that concentration of control is exactly what creates the opportunity.
Only about a quarter of small businesses have an established whistleblower or tip mechanism in place, compared to the vast majority of large organizations — and tips are consistently the single most common way fraud gets detected in the first place. Fewer eyes, fewer checks, fewer ways for a problem to surface before it compounds.
The Anatomy of an Internal Theft Scheme
Occupational fraud in small companies tends to cluster around a handful of recognizable patterns, and understanding them is the first step toward closing the gaps:
- Check and payment tampering. Someone with check-signing authority (or access to online banking credentials) writes payments to themselves, a shell vendor, or an account they control, then buries the transaction in the books under a legitimate-looking description.
- Expense reimbursement fraud. Inflated or entirely fabricated expense reports, submitted and approved by the same person who created them, or approved by someone who never actually checks receipts against the ledger.
- Skimming. Cash or payments are pocketed before they're ever recorded, so there's no paper trail pointing to the theft — the money simply never shows up in the books at all.
- Billing schemes. Fake invoices from a vendor that doesn't really exist (or doesn't really provide the goods/services billed), paid out through the normal accounts-payable process because nobody is cross-checking invoices against actual deliveries.
Corruption schemes — kickbacks, self-dealing, conflicts of interest — are also disproportionately common at small organizations, in part because a small company's approval chain is short enough that one compromised person can be the entire chain.
What all of these schemes have in common is that they rely on the absence of a second set of eyes. The person who initiates a transaction is also the person who approves it, records it, and reconciles it. When that's true, fraud isn't a matter of if — it's a matter of how long before it's noticed, and by then, how large the hole has grown.
Segregation of Duties: The Single Highest-Leverage Fix
The standard prescription from fraud examiners and CPAs alike is segregation of duties: no single person should be able to initiate, approve, and record a financial transaction end to end. Even in a company too small to have separate accounting, purchasing, and treasury departments, this principle can usually be applied with the resources already on hand:
- Split check-writing from check-approval. The person who prepares a payment shouldn't be the only person who can authorize it. Even a simple rule — anything over a set dollar threshold needs a second signature — closes an enormous hole.
- Reconcile bank statements independently. The bank reconciliation should be performed (or at least reviewed) by someone who did not initiate the transactions being reconciled. A business owner who never looks at the raw bank statement, and only sees numbers the bookkeeper has already summarized, has no independent check at all.
- Require documentation before payment, not after. Invoices, receipts, and purchase orders should be attached to the transaction before it's approved, not reconstructed after the fact if someone asks.
- Rotate or spot-check who touches the books. Even an annual look from an outside accountant — someone who wasn't involved in the day-to-day entries — can surface anomalies that a familiar, trusted routine would never flag.
- Make the ledger genuinely reviewable. This is where the tooling matters as much as the policy. A control is only as good as your ability to actually look at what happened.
That last point is where a lot of small businesses quietly fail, even when they intend to do everything right. If your financial records live inside a black-box app where transactions can be edited or deleted without a visible trace, "reviewing the books" often just means glancing at a dashboard summary generated by the same system a bad actor could manipulate. A system that makes every entry and every edit visible and traceable is a very different proposition — and it's a meaningful part of why plain-text, version-controlled accounting has become popular with technically-minded founders and finance teams who want a real audit trail, not just a polished report.
What This Means If You're the One Signing the Checks
Prevention doesn't require an internal audit department. The businesses that catch problems early tend to do a few unglamorous things consistently: someone other than the bookkeeper looks at the raw bank feed every month, unusual vendors get a second look before payment, and nobody — not even the most trusted long-tenured employee — has sole, unreviewed control over money leaving the business. Effective fraud prevention programs typically cost a small fraction of revenue, while the losses they prevent average around 5% of annual revenue in unchecked cases. That's a lopsided trade in favor of building the habit now, before a routine hire or a familiar face becomes the subject of a story like this one.
None of this requires assuming the worst about the people you work with. It requires building a system where trust doesn't have to be the only control in place — because when it's the only one, one person's bad decision becomes the whole company's crisis.
Keep Your Financial Records Transparent and Auditable
The lesson from cases like this isn't just "watch your bookkeeper" — it's that financial records should be structured so a review is actually possible, quickly, by anyone who needs to look. Beancount.io offers plain-text accounting with a full, tamper-evident change history baked in: every entry lives in version-controlled, human-readable files, so nothing gets buried or quietly edited out of sight. Get started for free and build your books on a system designed for transparency from the first transaction.