Cookie Consent by Free Privacy Policy Generator Fraud Risks That Can Change the Story of a Transaction | DoingBusiness.ro
loader
Fraud Risks That Can Change the Story of a Transaction

Fraud Risks That Can Change the Story of a Transaction

Author: Diana Raducanu, Senior Manager, Forensics, EY Romania

In practice, M&A due diligence highlights a recurring asymmetry: financial, tax, legal and operational risks are understandably prioritized and rigorously analysed, while fraud risks do not receive the same level of attention. Bringing these risks into the discussion in a transactional context may be perceived as a sensitive exercise, especially when the economic rationale of the transaction is compelling.

One practical consequence of this reluctance is that patterns of organizational culture, together with governance and internal control deficiencies, may remain insufficiently analysed during typical due diligence. The lack of specific procedures tailored to the transactional context may allow red flags related to potential irregularities to go unidentified in time or to remain undetected, and inherited fraud creates a significant risk exposure for the buyers.

In the local M&A landscape, this reluctance often stems from a gap between buyers’ and sellers’ expectations regarding organizational culture, governance and the control environment. Foreign investors often target local companies for their financial performance and growth potential, assuming the existence of governance standards and business practices capable of supporting sustainable financial models. These aspects, however, do not always match operational reality, with fraud risks being amplified by the interaction between commercial or financial pressures, control vulnerabilities and the tolerance of questionable organizational behaviours.

When Opportunity Meets the Capability

Fraud risks in a transactional context can be better understood by analysing the interaction between the four components of the fraud diamond: pressure, opportunity, rationalization and capability. This model was popularized by researchers David T. Wolfe and Dana R. Hermanson, building on criminologist Donald R. Cressey’s well-known fraud triangle1.

Thus, the need to close the transaction on favourable terms or to meet demanding financial targets creates pressure. Accelerated due diligence and transaction signing processes, as well as a deficient control environment, create opportunity. The justification of unethical practices through commercial objectives or by reference to protecting the organization’s value represents elements of rationalization, while the close involvement of senior management, in a position that may allow the circumvention of internal controls, completes the capability component.

The Effectiveness of Prevention as an Indicator of Organizational Maturity

Opportunity is one of the risk indicators highlighted by the fraud triangle/diamond2 that can be directly influenced by organizations. From this perspective, opportunity becomes particularly relevant for buyers, in the context of growing concern around the design and implementation of effective systems for the prevention and early detection of fraud risks.

Recent EU legislative developments on anti-corruption, as well as the introduction of the “failure to prevent fraud” offence in the UK, reinforce this shift in perspective. The focus is no longer limited to individual conduct or isolated misconduct; it increasingly extends to organizations’ responsibility for preventing, detecting and addressing misconduct. In a transactional context, a buyer should not ask only whether fraud has occurred, but also whether the control environment, compliance framework and governance bodies of the acquired organization would have been capable of preventing or detecting such an incident in a timely manner.

With regard to how the risk indicators in the fraud diamond may influence one another, an important point is highlighted in the report “Combatting Fraud in a Perfect Storm”3, published in November 2025 by the Association of Chartered Certified Accountants (ACCA) from the UK, namely that the rationalization of fraud is facilitated by a lack of trust in leadership. The report also notes that employees do not rationalize misconduct only under personal pressure, but also when they believe their leaders behave in the same way.

How Fraud Risks Evolve Across the Transaction Timeline

Fraud risks are not static, and fraud schemes may vary depending on when the associated risks materialize — before, during or after the transaction — and according to the dynamics of economic cycles. Before or during the transaction, the pressure to maintain a certain level of financial performance and financial position may favour the manipulation of financial indicators through aggressive revenue recognition, deferred recognition of expenses, corruption, overstatement of assets or understatement of liabilities. After the transaction, pressure may arise to justify shrinking margins and constrained liquidity, which may lead to procurement fraud, corruption, inventory theft, embezzlement, conflicts of interest or undisclosed arrangements with related parties.

In other words, due diligence processes capture organizations at a particular point in time, while fraud risks may become visible only when market conditions change and growth slows. These risks may also be amplified post-acquisition by specific organizational factors, such as employees’ reluctance to escalate misconduct due to existing loyalties, the perception of compliance initiatives as mere formalities or resistance to the changes introduced during the integration period.

In this context, it is also useful to distinguish between fraud generated or accelerated by transaction pressure and pre-existing fraud that may be concealed or presented in a misleading manner during the due diligence process. Such practices do not merely represent omissions of information; they may themselves constitute a form of fraudulent conduct with a direct impact on transaction risk. By acquiring a company, a buyer may inherit not only its legitimate business practices, but also the consequences and risks associated with any pre-existing fraudulent conduct.

What Red Flags Look Like in Practice

In such situations, forensic due diligence procedures become particularly relevant, as they may reveal red flags that would not emerge from traditional due diligence. A relevant example is the case of a foreign investor that, a few years ago, entered into a joint venture with a local landowner partner for the development of a production facility. The transaction was subsequently subject to a post-acquisition due diligence process from the perspective of FCPA requirements (Foreign Corrupt Practices Act, US).

In the initial stages, the analysis pointed to an apparently efficient construction and permitting process: short timelines, no bureaucratic bottlenecks and a smooth progression. From a fraud examiner’s perspective, it is precisely this unusual smoothness that may raise questions. A detailed analysis of this context showed that a significant proportion of the employees of the newly established company had family ties with decision-makers within the local mayor’s office. Although these family ties do inherently indicate the existence of corrupt practices, they become relevant when analyzed in the broader context of the transaction and corroborated with factors such as the absence of a competitive selection process, the existence of undeclared conflicts of interest and indications from internal correspondence of potential improper influence over the permitting process. Taken together, these elements outline a risk profile that may shift a due diligence review towards an investigation.

Another example of the relevance of anti-fraud due diligence procedures concerns the analysis of the supplier portfolio in situations where buyers become concerned about the causes of an unforeseen deterioration in post-acquisition performance indicators. Frequently, these procedures reveal a large number of small suppliers providing similar services without a clear justification, newly established suppliers engaged beyond their capacity or expertise, commercial relationships marked by preferential treatment, suppliers heavily dependent on the commercial relationship with the acquired organization, or suppliers in conflicts of interest with decision-makers.

Another tool that can add significant value in forensic due diligence, but which is generally overlooked or treated superficially, is the whistleblowing system. Although reviewing the policies and procedures governing reporting systems is typical in forensic due diligence, the difficult part lies in assessing the extent to which employees and third parties genuinely trust the available channels for reporting misconduct. In this respect, certain red flags may indicate trust issues in whistleblowing channels, such as a complete absence of reported incidents, high staff turnover with no incidents reported, complaints closed unusually quickly or without sufficient substantiation, investigations conducted by parties potentially targeted by the allegations or otherwise lacking objectivity, or indications of retaliation.

Technology represents another important differentiattor in forensic due diligence. They allow efficient and effective identification of potential conflicts of interest across the entire supplier, customer and employee population, the mapping and visualization of complex relationship networks, or the identification of document manipulation indications. A relevant example in this regard is a post-acquisition due diligence in which indications were identified that a contract had been backdated to justify revenue inflated through related-party transactions. The document was supposed to have been signed and scanned by two entities in the United Kingdom, before being sent to an entity in Korea. The automated analysis revealed that the electronic document had been generated after the end of the financial year, using a scanner marketed and predominantly used in Korea. Moreover, inconsistencies were identified in the document’s appearance and structure. These aspects also led to an investigation with legal implications.

As the previous examples also show, the relevant distinction is not only between conducting or not conducting forensic due diligence, but between staying  within a less intrusive but rather limited analysis and looking into less explored areas to draw meaningful connections between data, relationships and organizational behaviours.

In conclusion, forensic due diligence brings a distinct perspective to M&A by connecting financial red flags with the behavioural, cultural and governance factors that may amplify fraud risks. The added value of this type of due diligence does not result from analysing fraud risks in isolation, but from the way it complements financial, legal, tax, commercial and operational perspectives.

Well-known cases, such as HP’s acquisition of Autonomy , announced in 2011 and followed by allegations of accounting irregularities that allegedly led to an overstatement of the transaction price by almost GBP 700 million, show how profoundly fraud can change the story of a transaction. As a result, in a transaction, the essential question is not only how well the organization is performing, but also how that performance was achieved and how sustainable remains in the context of the changes brought about by the transaction, including from an ethical perspective.

                                                                                                                   ***

1Wolfe, D. T., & Hermanson, D. R. (2004). The Fraud Diamond: Considering the Four Elements of Fraud. The CPA Journal

2Cressey, D.R., (1953). Other People’s Money: A Study in the Social Psychology of Embezzlement, Free Press

3Association of Chartered Certified Accountants (ACCA). (2025). Combatting Fraud in a Perfect Storm. [accaglobal.com]

Authors

foto
ERNST & YOUNG SRL
   Update cookies preferences