AWRA OpsHub Search

Five Ways Money Leaves a Kenyan Business (And the Controls That Close Them)

Internal loss in Kenyan businesses is rarely dramatic and almost never technical. It runs through five well-worn paths, each of which needs a specific control combination to close — and each of which stays open in most SMEs because the same person does two jobs.

Security & Compliance Washingtone Aura 13 min read

Business owners who have been defrauded describe the same experience: not a discovery but a slow arithmetic problem. Margins that should be twenty per cent are fourteen and nobody can say why. Stock counts that never quite tie. A supplier whose prices seem high but who always delivers. Then somebody leaves, the numbers move, and the shape of it becomes visible in retrospect.

What follows is uncomfortable to write and more useful than a general appeal to good governance. These are the five paths money actually takes out of a Kenyan SME, with the control combination that closes each. None of them requires technical sophistication. All of them require a gap that exists in most small businesses for an entirely honest reason: there are not enough people, so one person does two jobs.

A necessary caveat before the list. The overwhelming majority of staff in the overwhelming majority of businesses are not doing any of this. The reason to close these paths is not suspicion of anyone — it is that an open path makes an honest person's work unprovable, and that is its own cost. A storekeeper who cannot demonstrate that a variance was not theirs carries a suspicion nobody has voiced.

One: the supplier who is also the buyer

The oldest scheme and still the most common. A supplier is created in the system, purchase orders are raised to it, invoices arrive, payments go out. The supplier is real in the sense of having a bank account and being registered; what it does not have is any goods.

It needs exactly two capabilities in one pair of hands: the ability to create a supplier and the ability to approve a payment. In a small finance team, that is one job description. And because the payments are individually unremarkable — the amounts are chosen to be boring — nothing surfaces until somebody reads the supplier list carefully, which typically happens for the first time during a fraud investigation.

What it looks like in the ledger

Supplier created, plausible name, no prior history Month 1
First payment — small enough not to require a second approval KES 84,000
Monthly thereafter, varied slightly to avoid a pattern KES 70–110,000
Months before anyone reads the supplier list 19
Total before discovery KES 1.7M

Nothing here is anomalous individually. The detection is not in the transactions; it is in the supplier list — a vendor with no goods received notes, no delivery documents and no contract, paid monthly for nineteen months.

The control that closes it

Supplier creation and payment approval must not sit with the same person, and new suppliers should require a second pair of eyes before their first payment. Then read the supplier list quarterly, sorted by payments received, and look for any vendor with no goods received notes against it. That last query is a ten-minute exercise that this scheme cannot survive.

Two: the price that is only slightly wrong

A genuine supplier, genuine goods, genuine delivery — and a price ten per cent above market, with the difference returning to the buyer privately. This is harder to detect than the ghost supplier because every document is real and the three-way match is perfect. Nothing is missing. The price is simply wrong, and price is a judgement.

What makes it survive is single-sourcing. If one supplier has provided an item for three years and no competing quote has ever been obtained, there is no benchmark against which the price is wrong. The scheme is protected not by concealment but by the absence of comparison.

The control that closes it

Competing quotes above a threshold you set, recorded in the system rather than in an email, and a periodic review of price trends by item and supplier. The question that exposes it is not "is this price fair" but "when did we last test it" — and if the answer is never, that is the finding regardless of whether anyone is taking a margin.

Three: the adjustment that covers the count

Goods leave without a sale. The count that would reveal the shortfall is performed by the person who removed them, and the difference is written off as damage, expiry or a correction. Every individual adjustment is small and plausible. The pattern is only visible in aggregate, and the aggregate is rarely looked at.

This is the scheme that makes people believe theft is undetectable, and it is really a measurement problem. If adjustments are unlimited, unapproved and unaggregated, they are a general-purpose tool for making any physical reality match any recorded one. The full treatment is in stock control in Kenya, which argues that theft only becomes investigable once the procedural leaks around it are closed.

The control that closes it

Adjustments require a reason and an approver above a threshold, the person who counts is not the person who controls the stock, and adjustments are reviewed monthly in aggregate by reason, by item and by person. The aggregate view is the control — individually these are all defensible, and that is exactly the point.

Four: the employee who does not exist

A name on the payroll with a bank account or mobile money number that belongs to somebody else. It survives because payroll is treated as a finance process rather than an HR one, and because nobody reconciles the payroll register against an actual list of people who came to work.

The variant that catches larger organisations is subtler: a real employee who left, whose record was never deactivated, whose bank details were quietly changed after departure. That one needs no fictional person at all.

The control that closes it

Employee record maintenance and payroll processing separated, changes to bank details treated as high-risk events that are reviewed rather than merely logged, and a monthly reconciliation of headcount from the payroll register against the leaver process. The leaver process is the load-bearing part — see employee records and contracts and PAYE, NSSF and SHIF payroll.

Five: the till

Cash removed at the point of sale, concealed by any of several mechanisms: a sale not rung up at all, a refund processed against nothing, a discount applied and the difference pocketed, or cash simply removed and the shortage absorbed because variance is never investigated.

The reason retail cash loss is chronic rather than occasional is that most tills are reconciled loosely. If the cashier knows the expected figure before counting, the count becomes a target rather than a measurement, and a variance can be made to disappear before it is recorded. The mechanics are in POS shift reconciliation, including the honest limit that a blind count is a discipline rather than something the system can enforce.

The control that closes it

A float recorded at open, cash removals recorded as drops rather than absences, a count performed without the expected figure visible, variance recorded per shift per person rather than absorbed, and refunds and discounts attributable to a named cashier. Then look at variance by person over a month — a consistent small shortage from one person is the signal, and a single bad night is not.

The pattern behind all five

Every scheme above requires two capabilities in one pair of hands, and every control above works by separating them. That is the entire theory, and it is why segregation of duties is the oldest control in the book and the first one small teams abandon.

Scheme The two capabilities it needs The aggregate view that exposes it
Ghost supplier Create a supplier + approve a payment Suppliers with payments but no goods received notes
Inflated price Select the supplier + set the price unchallenged Price trend by item and supplier over time
Adjustment cover Control the stock + perform the count Adjustments by reason, by item and by person, monthly
Ghost employee Edit employee records + run payroll Payroll headcount against the leaver process
Till skimming Take the cash + report the variance Variance by person over a month, not per shift

The third column is the more useful half of that table, because the separation of duties is often genuinely impossible in a small team — there is one storekeeper, and they will be the one who counts. Where you cannot separate, you compensate by making the aggregate visible to someone who is not involved. A storekeeper who knows the monthly adjustment summary goes to the owner is in a completely different position from one who knows it goes nowhere.

Where you cannot separate the duties, make the aggregate visible to someone who is not involved. Detection is a weaker control than prevention, and it is enormously stronger than nothing.

What a system can and cannot do about this

Fraud controls — the straight answer

What AWRA OpsHub does today

  • Approval thresholds and workflow on requisitions, purchase orders and payments, so a second pair of eyes is a rule rather than a habit.
  • Permissions granular enough to separate the pairs above, so creating a supplier and approving a payment can be genuinely different people.
  • Adjustment reasons and approval, with adjustments recorded as documents rather than as silent quantity edits.
  • Goods received notes independent of the purchase order, so what arrived is recorded by whoever received it.
  • Shift-level cash reconciliation with float, recorded drops, expected versus counted cash and variance per shift and per person.
  • An audit log capturing actor, action, IP, session and affected record for every action that leaves a trace.
  • Reporting and dashboards that make the aggregate views in the third column above producible rather than theoretical.

What it does not do

  • No fraud detection. Nothing scores transactions for suspicion, flags an unusual supplier, or alerts you to a pattern. Every aggregate view in this article is a report somebody has to look at on a rhythm.
  • No automatic detection of dangerous permission combinations. The system will not warn you that one person can create suppliers and approve payments — that is a review you run against your own role list.
  • No enforced discount approval at the till. Discounts are recorded and attributable to a cashier, but there is no approver gate on them.
  • No enforcement of a blind count. Whether the cashier sees the expected figure before counting is a supervisory discipline, and every variance figure's credibility depends on it.
  • No market price benchmarking. The system holds your own price history, which is what makes a trend visible; it has no external reference for whether a price is fair.

The honest summary is that software prevents the schemes that separation of duties prevents, and detects nothing on its own. Every one of these controls is a rule you configure plus a report somebody reads. A business that buys the system and skips the second half has bought the record-keeping and none of the protection.

Where to start if you have never looked

Not with an investigation. Start with the five aggregate views, because they are quick, they are not accusatory, and they establish a baseline you can compare against next quarter.

  1. Read the supplier list, sorted by amount paid

    Look for any supplier with payments but no goods received notes, and any supplier you cannot immediately explain. Ten minutes, and the ghost supplier scheme cannot survive it.

  2. Pull adjustments for the last quarter, grouped by reason and by person

    You are not looking for a large adjustment. You are looking for a consistent small one from one source, which is the shape this takes.

  3. Reconcile payroll headcount against people who actually work there

    Names, not numbers. Then check whether any bank or mobile money details changed in the last six months and who changed them.

  4. Look at till variance by person over a month

    A single bad night is noise. A consistent shortage from one person is a signal, and consistency is only visible across a month.

  5. Check the four dangerous permission combinations

    Against your own role list, by hand. Nothing will flag them for you — the list is in access control.

  6. Then set the rhythm

    These five views, quarterly, by a named person who is not involved in any of the processes. The rhythm is the control; a single look is only a baseline.

What to do if you find something

Stop reading dashboards and get advice — legal, and depending on scale, a forensic accountant. Do not confront, do not delete anything, and do not adjust access in a way that signals you are looking, because the first casualty of a premature confrontation is the evidence. Preserve the records, including the audit log, and take advice on the sequence before you act.

Our take

Assume the five paths are open in your business, because in most Kenyan SMEs at least three of them are, for entirely honest reasons of headcount. Close what you can by separating the two capabilities each scheme needs. Where you genuinely cannot separate — one storekeeper, one cashier — compensate by making the aggregate view visible to someone uninvolved, on a rhythm, and let people know it is looked at. And be clear with yourself that no software detects any of this: every control here is a rule you configure plus a report somebody actually reads.

See the approval and audit controls

Approval thresholds on requisitions, orders and payments, adjustments as documents with reasons, receipts independent of the buyer, and shift-level cash reconciliation with variance per person.

Explore financial governance

Frequently asked questions

Is internal fraud really common in Kenyan SMEs?

Loss through these paths is common; deliberate fraud is much rarer than the paths being open. That distinction matters because the reason to close them is not suspicion of your staff. An open path makes an honest person's work unprovable — a storekeeper who cannot demonstrate that a variance was not theirs carries a suspicion nobody has voiced, and that is a real cost even where nothing was ever taken.

We only have one storekeeper. How can we separate the count from the custody?

Often you cannot, and pretending otherwise produces a control that exists on paper only. The workable substitute is compensating detection: the person who controls the stock still counts it, and the monthly adjustment summary — by reason, by item, by person — goes to someone uninvolved, on a fixed rhythm, and everyone knows it does. Detection is weaker than prevention and enormously stronger than nothing.

Will the system flag suspicious transactions for us?

No. There is no fraud detection, no anomaly scoring and no alerting on unusual suppliers or patterns. Every aggregate view described in this article is a report someone has to look at on a rhythm. That is worth being blunt about, because a business that buys the system and skips the review has bought the record-keeping and none of the protection.

Which single control gives the most protection for the least effort?

Separating the person who orders from the person who receives. It closes or weakens three of the five paths, it costs nothing beyond a decision, and it is the control small teams abandon first — usually during the first busy week, for reasons that felt sensible at the time. Second place goes to requiring a second approval before a new supplier's first payment.

What should we do if we think we have found something?

Get advice before acting — legal, and a forensic accountant if the scale warrants it. Do not confront anyone, do not delete anything, and do not visibly change their access, because a premature confrontation destroys evidence and the audit log is the thing you most need intact. Preserve the records first and take advice on the sequence.

Help Center

Need a quick answer while you read?

Run inventory, procurement, assets, sales, and field work with approved AWRA guidance for setup, migration, integrations, security, pricing, and support.

Search all approved AWRA public help articles.

Open Help Center