Audit & Risk

Fraud Risk in Emerging Markets: A Framework for Boards

In emerging markets, fraud is a board problem. Here is a framework for handling it.

By Fiscal Metrics Research15 August 2026 659
Fraud Risk in Emerging Markets: A Framework for Boards
· Unsplash

The ₹26 lakh golf set

When SEBI issued its interim order against Gensol Engineering in April 2025, the detail that travelled fastest wasn't the ₹977.75 crore in loans from IREDA and PFC, or the roughly ₹207 crore gap between what was borrowed to buy electric vehicles and what was actually delivered. It was a golf set. Twenty-six lakh rupees, bought with money meant for cars.

The regulator's language was unusually direct: company funds had been routed to related parties and spent on unconnected items, as though they were the promoters' piggybank. Forged “conduct letters” went to credit rating agencies to paper over defaults. Cash moved through a dealer, into promoter-linked entities, and out again — some of it into an apartment at DLF Camellias. By then Gensol had roughly 110,000 shareholders, up from 155 at the time of its 2019 listing.

None of this was invisible. It was unexamined by the people whose job it was to examine.

That is the recurring shape of fraud risk in emerging markets. Rarely exotic. Rarely technically clever. Mostly slow, mostly boring, and mostly living in the gap between what a board is told and what a board verifies.

What the 2026 data actually says

The Association of Certified Fraud Examiners released Occupational Fraud 2026: A Report to the Nations in May — its fourteenth edition, built from 2,402 investigated cases across 143 countries. Fraud examiners still estimate that a typical organisation loses around 5% of revenue each year. The median case cost $104,000, the average $1.457 million, and one case in five ran past a million dollars. The typical scheme lasted twelve months before anyone noticed.

Two findings should hold a director's attention.

First, corruption now shows up in 45% of cases, against 10% in the first report thirty years ago. Second, the fraudster has moved up the org chart. Employees and managers each account for 41% of cases; owners and executives for 16%. But median losses caused by that last group run more than nine times higher than those caused by employees.

Regionally it sharpens further. Presenting the 2026 data at FraudCon in August, the ACFE's India chapter put Southern Asia's median loss at $100,000 per case, with 67% of cases involving corruption — half again the global rate. Emerging markets don't simply have more fraud. They have a different mix of it.

Why the terrain is different

Four structural features do most of the work.

Ownership is concentrated. The OECD's Corporate Governance Factbook 2025 found that in 34 of 51 jurisdictions surveyed, the three largest shareholders hold more than half the average listed company's equity. Where control sits that tightly, related-party transactions stop being a disclosure formality and become the main event. Regulators have adjusted: the share of jurisdictions requiring board approval for significant RPTs climbed from 54% in 2014 to 87%.

External discipline has loosened. India scored 39 on Transparency International's Corruption Perceptions Index 2025, ranking 91st of 182 — an improvement of five places, but still below a global average that itself slipped to 42 for the first time in over a decade. Meanwhile one backstop that many emerging-market groups had quietly priced in has weakened: the United States paused FCPA enforcement in February 2025 and resumed it in June under guidelines narrowed to conduct touching American interests. Whatever one makes of that policy, it means less borrowed deterrence.

Growth outruns controls. India's banking numbers illustrate the lag neatly. In 2025-26, banks and financial institutions reported 10,114 fraud cases involving ₹48,021 crore — well under half the 23,722 cases of the previous year, but 46% more money. Advances accounted for about 85% of the value. And ₹30,199 crore of the total came from 314 legacy cases reclassified after a Supreme Court judgment. The frauds weren't new. The reporting was.

Assurance is thin where it matters. Group structures sprawl across subsidiaries, joint ventures and distributor networks long before internal audit is funded to follow them. The second and third lines of defence tend to arrive a year or two after the risk does, and independent directors are frequently asked to supervise operations in five states and two countries on the strength of a quarterly pack.

Fraud in emerging markets seldom announces itself as fraud. It arrives as an unusually accommodating vendor, a subsidiary that always hits its number, and a relationship the board is told is far too important to disturb.

A framework a board can actually use

The COSO/ACFE Fraud Risk Management Guide, updated in 2023, organises anti-fraud work around five principles: fraud risk governance, fraud risk assessment, preventive and detective control activities, investigation and corrective action, and monitoring. That is the right spine. Here is what it looks like when directors — rather than the compliance function — carry it.

1. Own the fraud risk assessment; don't just receive it. Most boards are handed one. Few take it apart. A useful assessment is scheme-specific rather than category-specific: not “procurement risk” but “a category manager splits purchase orders below the approval threshold and routes them to a vendor his brother-in-law owns.” For each scheme, ask four things — who could run it, which control would stop it, when that control was last tested, and what the test found. If the assessment is more than a year old, it describes a company that no longer exists.

2. Follow the money out of the group. In concentrated-ownership markets, value leaves through related parties and third parties, not the petty cash box. Boards should insist on a mapped view: every agent, distributor, dealer and intermediary above a value threshold; who beneficially owns them; when they were last screened; and which were onboarded in the past year without a competitive process. Gensol's circular funding ran through a dealer. So do most of the others. The test is not whether a contract exists; it is whether anyone in the room can explain what the counterparty actually does for the money.

3. Make it safe — and easy — to tell you. Tips detected 43% of cases in 2026, nearly three times internal audit's 15%, and more than half of those tips came from employees. The economics are stark: organisations with a formal reporting mechanism recorded a median loss of $100,000 and caught schemes in eleven months, while those without lost a median $150,000 and took seventeen. Note also that email and web channels have overtaken telephone hotlines — which matters in markets where a phone call feels traceable and a caller feels exposed. Test the channel the way you would test any control: submit a case, trace routing, escalation and closure, and report cycle time to the audit committee.

4. Detect without waiting to be told. Management review, proactive data monitoring and surprise audits were each associated with lower losses and faster detection. Fraud awareness training more than doubled the rate of employee tips; organisations that trained both staff and management saw median losses of $84,000 against $150,000 where neither group was trained. None of that is expensive. All of it is measurable — which is rather the point, because a board can put days-to-detection on the scorecard and then watch the number move.

5. Rehearse the response before you need it. Section 143(12) of the Companies Act, 2013 requires an auditor who has reason to believe an offence of fraud is being committed to report it — to the Central Government above the prescribed threshold, and to the audit committee or board below it. Directors should know, before the call comes, who leads an investigation, who preserves data, when counsel is engaged, and what gets disclosed when. IndusInd Bank's 2025 sequence is instructive on pace: an internal review flagged derivatives discrepancies in March; PwC quantified a ₹1,979 crore hit in April; Grant Thornton reported root cause days later; and by 21 May the bank had disclosed a suspected internal fraud of about ₹173 crore in its microfinance book. That is roughly ten weeks from first signal to public disclosure of suspected employee involvement.

The override problem

More than half the 2026 cases involved either a missing control or an overridden one. The second word is the one that should keep directors awake, because override is almost always a senior-person move, and no control framework survives it unassisted.

The available counterweight is behavioural. Eighty-four per cent of perpetrators displayed at least one red flag before detection — living beyond their means, financial difficulty, unusual closeness to a vendor, reluctance to share duties. Boards cannot audit these. They can notice them. And they can stop treating “he's been here twenty years” as though it were a control. Long tenure buys trust; it also buys knowledge of exactly which reconciliation nobody checks.

Three questions

A board does not need to become a forensic unit. It needs to stop accepting comfort as evidence. At the next audit committee, three questions will surface more than a quarter's worth of dashboards: which fraud schemes are we most exposed to, what would show up in our data if one were running right now, and who last looked?

If nobody can answer the third, the framework isn't working yet.

 

Sources

ACFE — Occupational Fraud 2026: A Report to the Nations — primary report page

ACFE — Press release: 84% of fraudsters show at least one behavioral red flag (12 May 2026) — headline 2026 statistics

ACFE Insights — Key Findings from Occupational Fraud 2026 — scheme mix, detection, controls, training

COSO — Fraud Deterrence / Fraud Risk Management Guide, Second Edition (2023) — the five fraud risk management principles

ACFE India Chapter — FraudCon 2026 (via The Tribune, 8 August 2026) — Southern Asia median loss and corruption rate

OECD — Corporate Governance Factbook 2025 — ownership concentration data

OECD — How are shareholder rights evolving (January 2026) — related-party transaction approval trend

Transparency International — Corruption Perceptions Index 2025 — global average and methodology

Transparency International — India country page — India score and rank

Reserve Bank of India — Annual Report 2025-26 — bank fraud reporting data

Business Standard — Legacy cases lifted bank fraud to ₹48,021 crore in FY26 (29 May 2026) — FY26 fraud breakdown

SEBI — Interim Order in the matter of Gensol Engineering Limited (15 April 2025) — primary order

SEBI — Confirmatory Order, Gensol Engineering Limited (30 July 2025) — confirmation of interim directions

Business Standard — Sebi bars Gensol Engineering promoters for alleged fund diversion — case background

Business Standard — External audit agency uncovers ₹1,979 crore impact on IndusInd Bank — PwC quantification

Business Standard — Incorrect accounting of derivatives trades led to IndusInd Bank fiasco: GT — root-cause findings

Business Standard — IndusInd Bank reveals ₹173 cr fraud in microfinance during internal audit — suspected internal fraud disclosure

Harvard Law School Forum on Corporate Governance — DOJ Resumes FCPA Enforcement with New Guidelines — FCPA pause and resumption

DLA Piper — FCPA year in review: enforcement trends and what's ahead in 2026 — 2025-26 enforcement posture

Ministry of Corporate Affairs — The Companies Act, 2013 — Section 143(12) auditor fraud reporting

 

Discussion

0 Comments

Sign in to join the discussion.

Related reading