{"id":28244,"date":"2026-06-01T04:00:00","date_gmt":"2026-06-01T02:00:00","guid":{"rendered":"https:\/\/www.thebrokernews.ch\/?p=28244"},"modified":"2026-05-31T08:42:47","modified_gmt":"2026-05-31T06:42:47","slug":"fraud-is-not-bad-luck-fraud-is-the-receipt","status":"publish","type":"post","link":"https:\/\/www.thebrokernews.ch\/en\/fraud-is-not-bad-luck-fraud-is-the-receipt\/","title":{"rendered":"Fraud is not bad luck &#8211; fraud is the receipt"},"content":{"rendered":"<div class=\"ccfic\"><span class=\"ccfic-text\">Thomas Schubert weiss, wie Compliance vom Kostentreiber zum Wettbewerbsvorteil wird.<\/span><\/div>\n\n<p class=\"wp-block-paragraph\"><strong>Insurance fraud rarely begins with criminal energy, but rather with open doors in one&#8217;s own system. In his trenchant analysis, Thomas Schubert shows why fraud is not the real problem, but the symptom of a governance failure. And why compliance should no longer be a cost driver, but a strategic competitive advantage.  <\/strong><br\/><br\/>And you think a compliance department, a manual and a certificate on the wall are enough. Never mind, the clock is ticking. For an average of twelve months. Tik-tak, tik-tak, tik-tak.   <\/p>\n\n<p class=\"wp-block-paragraph\">Every time an insurance fraud goes undetected, a door has been left open.<\/p>\n\n<p class=\"wp-block-paragraph\">Not through misfortune. Not through criminal energy alone. But because someone forgot to close the door or never intended to close it.  <\/p>\n\n<p class=\"wp-block-paragraph\">FRAUD is not the problem. Fraud is the symptom. The real problem is governance failure.  <\/p>\n\n<p class=\"wp-block-paragraph\">Those who understand this not only change their view of compliance. They change the way they think and act. <\/p>\n\n<h6 class=\"wp-block-heading\">The fraud triangle: the only factor you can control<\/h6>\n\n<p class=\"wp-block-paragraph\">Scientists have been explaining white-collar crime for decades using the fraud triangle. Three factors have to come together for fraud to occur: <strong>Pressure, rationalization<\/strong> and <strong>opportunity<\/strong>. <\/p>\n\n<p class=\"wp-block-paragraph\">You can hardly control the pressure an employee is under. Whether someone is in financial difficulties, under pressure to perform or justifies their actions internally is beyond your control. <\/p>\n\n<p class=\"wp-block-paragraph\">But the opportunity can be eliminated.<\/p>\n\n<p class=\"wp-block-paragraph\">Fraud thrives where there are holes in control structures. Where a single person controls processes from recording to payment without cross-checking. Where access rights are not actively managed. Where the Board of Directors nods without understanding what it is approving.   <\/p>\n\n<p class=\"wp-block-paragraph\">What specifically eliminates opportunities: the dual control principle for critical approvals. The consistent separation of tasks. Whoever enters a transaction may not release it. Release limits that automatically trigger a second signature. Identity and access management that immediately revokes access rights when a person changes jobs or leaves the company.    <\/p>\n\n<p class=\"wp-block-paragraph\">These are not IT issues. These are governance measures and decisions. And they are the first question I clarify with a management team before we talk about technology or regulation.  <\/p>\n\n<p class=\"wp-block-paragraph\"><strong><em>Question for you: Can payouts be triggered in your organization today without cross-checking and who would notice?<\/em><\/strong><\/p>\n\n<h6 class=\"wp-block-heading\">What the law requires of you and what it costs if you ignore it?<\/h6>\n\n<p class=\"wp-block-paragraph\">Governance failure is not a moral issue. It is a liability issue. <\/p>\n\n<p class=\"wp-block-paragraph\">Swiss law is clear on this point. <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/cc\/27\/317_321_377\/de#art_716_a\" target=\"_blank\" rel=\"noopener\">Art. 716a of the Swiss Code of Obligations<\/a> obliges the Board of Directors to exercise non-transferable overall supervision of risk management. Fraud prevention is therefore not the responsibility of the compliance officer, it is the responsibility of the Board of Directors. Anyone who neglects this duty is personally liable under <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/cc\/27\/317_321_377\/de#art_754\" target=\"_blank\" rel=\"noopener\">CO Art. 754<\/a> for any resulting damages. Negligence is sufficient.   <\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.fedlex.admin.ch\/eli\/cc\/54\/757_781_799\/de#art_146\" target=\"_blank\" rel=\"noopener\">StGB Art. 146<\/a> regulates fraud as a criminal offense with a prison sentence of up to five years or a fine. <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/cc\/54\/757_781_799\/de#art_158\" target=\"_blank\" rel=\"noopener\">Art. 158 of the Swiss Criminal Code (StGB<\/a>), breach of trust, applies directly to those who damage financial interests entrusted to them. This explicitly includes managers in brokerage companies. <\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.fedlex.admin.ch\/eli\/cc\/2005\/734\/de#art_41\" target=\"_blank\" rel=\"noopener\">VAG Art. 41<\/a> requires personal guarantee, demonstrable good reputation and integrity. Ordinance on the Supervision of Private Insurance Companies (SO) Art. 188 prescribes the appropriate business organization. <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/cc\/2008\/736\/de#art_29\" target=\"_blank\" rel=\"noopener\">FINMAG Art. 29<\/a> requires immediate reporting of significant incidents. <\/p>\n\n<p class=\"wp-block-paragraph\">FINMA has made it clear: &#8220;We didn&#8217;t know&#8221; no longer applies. Those who should have known will be held responsible. Ignorance is no defense against punishment!  <\/p>\n\n<p class=\"wp-block-paragraph\">For brokers in the EU, there is also the <a href=\"https:\/\/www.epo.org\/de\/legal\/case-law\/2025\/clr_ii_d_2_4_3.html\" target=\"_blank\" rel=\"noopener\">IDD reversal of the burden of proof<\/a>. If the consultation protocol is missing, the broker must prove that they provided correct information in the event of a claim. Without documentation, this is virtually impossible. They are directly liable.   <\/p>\n\n<p class=\"wp-block-paragraph\"><strong><em>Question for you: Does your company now have clear rules on who informs the regulator within 24 hours of a fraud incident and according to what protocol?<\/em><\/strong><\/p>\n\n<h6 class=\"wp-block-heading\">The perpetrator is often in their own home<\/h6>\n\n<p class=\"wp-block-paragraph\">That&#8217;s the part nobody likes to hear.<\/p>\n\n<p class=\"wp-block-paragraph\">According to the ACFE (Association of Certified Fraud Examiners) and the PwC Survey 2024, the crime is discovered internally in around 35% of all fraud cases. Often because the perpetrator is internal. A typical fraud case remains undetected for an average of 12 months. Twelve months in which damage accumulates, evidence is blurred and networks grow.   <\/p>\n\n<p class=\"wp-block-paragraph\">Insider fraud is structurally different from external fraud. External fraudsters bypass your systems. Internal perpetrators know the system and exploit the loopholes that their position opens up for them.  <\/p>\n\n<p class=\"wp-block-paragraph\">The consequence: classic perimeter security is not enough. Identity and access management must be actively managed. Access rights must not be allowed to accumulate silently. Behavioral anomalies, unusual access patterns, transactions outside of business hours, data exports in unusual volumes must be visible in real time.   <\/p>\n\n<p class=\"wp-block-paragraph\">Good governance creates the framework conditions for this. Whistleblowing systems are not a nice-to-have function, but are measurably effective: organizations with structured reporting channels detect fraud twice as quickly and record 50 percent lower financial losses on average. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong><em>Question for you: Who in your organization today has access to things that they no longer need for their current role and when was this last checked?<\/em><\/strong><\/p>\n\n<h6 class=\"wp-block-heading\">Where do you stand? Do you know the GRC maturity model for fraud prevention <\/h6>\n\n<p class=\"wp-block-paragraph\">Fraud security is not an on\/off switch. Every organization has a maturity level. The question is not whether you have a system. The question is to what extent it works.   <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Level 1, Reactive<\/strong>: Fraud is discovered after the loss has occurred. Control measures are only introduced after something has gone wrong. Many organizations find themselves here without knowing it.  <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Level 2, rule-based<\/strong>: There are guidelines, checklists, compliance manuals. Formal requirements are met. But the controls are static. Professional fraudsters know the rules and deliberately circumvent them.   <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Level 3, risk-oriented<\/strong>: Risks are systematically identified, assessed and prioritized. The internal control system (ICS) is actively managed. Compliance controls are checked for their effectiveness, not just for their existence. Continuous monitoring replaces the annual spot check.   <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Level 4, Proactive<\/strong>: AI-supported anomaly detection in real time. Fraud scenarios are systematically run through. The system learns from every incident. Regulators today demand precisely this level: not proof that controls are in place, but proof of the effectiveness of the controls, in real time.   <\/p>\n\n<p class=\"wp-block-paragraph\">As a C-level sparring partner, I find that most organizations believe they are at level 3. The risk-based process audit then usually shows that they are at level 2, with isolated elements of level 3. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong><em>Question for you: At what level would your internal auditors classify your company today and at what level do you see yourself?<\/em><\/strong><\/p>\n\n<h6 class=\"wp-block-heading\">Compliance as a control system, not a checklist<\/h6>\n\n<p class=\"wp-block-paragraph\">An effective compliance management system in accordance with ISO 37301 is based on three operational pillars.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>The internal control system (ICS) is the operational backbone<\/strong>. It defines which controls apply at which process points: The dual control principle, separation of functions, release limits. The ICS not only protects against external fraud. It protects the management from itself: Those who have not built in controls cannot claim ignorance in an emergency.   <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Continuous monitoring replaces random sampling<\/strong>. Instead of checking 5 percent of transactions once a year, rule-based systems analyze all transactions in real time (increasingly AI). Duplicate invoices. Postings outside of business hours. Payments to newly recorded accounts shortly after they are created. These patterns are invisible to a clerk. For an algorithm, they are routine.      <\/p>\n\n<p class=\"wp-block-paragraph\">ISO 37301 provides the framework: an internationally recognized standard for compliance management systems that not only regulates the &#8220;what&#8221;, but also the &#8220;how&#8221;: risk assessment, action plan, effectiveness testing, management responsibility. For brokers, for example, who want to position themselves vis-\u00e0-vis insurers and FINMA, an <strong>ISO 37301-compliant structure<\/strong> is a demonstrable sign of quality. <\/p>\n\n<h6 class=\"wp-block-heading\">The blind spot: third parties and risk appetite<\/h6>\n\n<p class=\"wp-block-paragraph\">According to the PwC Survey 2024, 42% of companies have no structured risk management for third parties. No risk scoring for suppliers, partners or subagents. <\/p>\n\n<p class=\"wp-block-paragraph\">This is acute in the brokerage sector. Anyone who places business via third parties or uses subagents often assumes their risk profile without knowing it. Reputational damage caused by a sub-agent affects the broker directly. FINMA is investigating this.   <\/p>\n\n<p class=\"wp-block-paragraph\">At the same time, many organizations are missing the most fundamental of all risk questions: What is our risk appetite for fraud? What is our risk tolerance? These two terms sound academic. They are not. Risk appetite defines which fraud risks an organization consciously accepts because the control costs would be disproportionate. Risk tolerance defines the limit at which a measure becomes mandatory.     <\/p>\n\n<p class=\"wp-block-paragraph\">Without these definitions, every compliance investment is a gut decision. With them, it becomes a strategic management decision and the basis for prioritizing measures. <\/p>\n\n<p class=\"wp-block-paragraph\">That is the difference between a compliance manual and a genuine GRC system.<\/p>\n\n<h6 class=\"wp-block-heading\">AI as a weapon against crime opportunities<\/h6>\n\n<p class=\"wp-block-paragraph\">Traditional, rule-based control systems have a structural problem: professional fraudsters know the rules. They deliberately circumvent them. <\/p>\n\n<p class=\"wp-block-paragraph\">At the same time, AI has dramatically accelerated the attack side. A credible scam email that used to take 16 hours of manual preparation is now generated by AI in 5 minutes. AI-supported deepfake attacks have increased by over 51 percent.  <\/p>\n\n<p class=\"wp-block-paragraph\">On the defense side, AI is breaking the pattern. Machine learning, predictive analytics, deep learning. That&#8217;s the difference between a static wall and an adaptive immune system.  <\/p>\n\n<p class=\"wp-block-paragraph\">The system recognizes new patterns before they are included in the rule catalog. Fraud scoring automatically evaluates every reported loss based on hundreds of parameters. Graph technology visualizes relationship networks and uncovers organized fraud rings that remain invisible to human auditors.  <\/p>\n\n<p class=\"wp-block-paragraph\">The human-in-the-loop approach (HITL) remains crucial: clear cases go to fast automated regulation. High-risk cases end up with specialized investigators. And the AI must always be able to explain why it has classified a case as suspicious. This for case handlers, courts and regulators. Only explainable results are legally usable.    <\/p>\n\n<h6 class=\"wp-block-heading\">The figures that belong in strategic planning<\/h6>\n\n<p class=\"wp-block-paragraph\">White-collar crime is not a marginal phenomenon. In Germany, registered white-collar crimes rose by 57.6% to over 61,000 cases in 2024. White-collar crime accounts for around 1 percent of all criminal offenses. However, it causes over 35 percent of total monetary losses.   <\/p>\n\n<p class=\"wp-block-paragraph\">Every franc lost through fraud costs a company 4.18 times as much, calculated over direct losses, internal investigation costs, external experts and reputational damage. For financial institutions, this multiplier rises to 5.37. <\/p>\n\n<p class=\"wp-block-paragraph\">Non-compliance costs are estimated to be 2.71 times the implementation costs of an effective compliance system across all industries. They pay in any case. The only question is whether it is proactive or reactive.  <\/p>\n\n<p class=\"wp-block-paragraph\">On the other hand: Investments in modern fraud management systems often pay for themselves in less than six months. GRC platforms show an ROI of over 200 percent over three years. A broker with demonstrably superior control processes becomes the preferred partner for insurers seeking high quality portfolios, with an impact on brokerage terms and product access that no marketing budget can buy.  <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>As a C-level sparring partner, I&#8217;ll say it straight away: these figures belong in strategic planning. Not in the compliance manual. <\/strong><\/p>\n\n<p class=\"wp-block-paragraph\"><em><u>From practice<\/u>: A large Swiss insurance group. Several countries. A compliance system that worked on paper. In reality: Outdated, neglected, considered unimportant.   <\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><em>I came on board as Transformation Lead. My job was to make the regulatory infrastructure fit for FINMA, FMA, IVASS and a changing AML\/KYC landscape. <\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><em>What I found was not a scandal. It was something more dangerous from the &#8220;that&#8217;s not important&#8221; past. <\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><em>An analysis showed that employees had accumulated access rights in Identity and Access Management (IAM) over the years. On systems that they no longer needed for their current role. No malicious intent. Not a clean process. No control. The classic opportunity structure from the fraud triangle, quietly growing under the radar of the wrong compliance routine.     <\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><em>We have closed it. IAM restructured. AML\/KYC processes streamlined. ICS and CMS operationally updated.   <\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><em>The most important realization for me was not of a technical nature. The management knew that something was wrong. But nobody had the mandate to make it visible. The costs were supposedly too high. There were no experts in the company who knew how to tackle the issue. There was no sparring partner who asked the uncomfortable questions and recognized the deeper connections.     <\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><em>And that is exactly my role.<\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><strong>TURNING REGULATION INTO VALUE!<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Thomas Schubert, <a href=\"https:\/\/solexa.ch\/\" target=\"_blank\" rel=\"noreferrer noopener\">solexa.ch<\/a><br\/>Mr. #DeedsCountMore, turns compliance from a cost driver into a competitive advantage<\/p>\n\n<p class=\"wp-block-paragraph\">Read also: <a href=\"https:\/\/www.thebrokernews.ch\/en\/the-smoke-detector-that-nobody-installed\/\">The smoke alarm that nobody installed<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Insurance fraud rarely begins with criminal energy, but rather with open doors in one&#8217;s own system. In his trenchant analysis, Thomas Schubert shows why fraud is not the real problem, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":28243,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_price":"","_stock":"","_tribe_ticket_header":"","_tribe_default_ticket_provider":"","_tribe_ticket_capacity":"0","_ticket_start_date":"","_ticket_end_date":"","_tribe_ticket_show_description":"","_tribe_ticket_show_not_going":false,"_tribe_ticket_use_global_stock":"","_tribe_ticket_global_stock_level":"","_global_stock_mode":"","_global_stock_cap":"","_tribe_rsvp_for_event":"","_tribe_ticket_going_count":"","_tribe_ticket_not_going_count":"","_tribe_tickets_list":"[]","_tribe_ticket_has_attendee_info_fields":false,"footnotes":""},"categories":[5100,12135,5134],"tags":[12345,5289,6000,9875,12343,12346,7026,12344,12348,12347],"class_list":["post-28244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-current","category-columns","category-general","tag-bad-luck","tag-compliance-en","tag-finma-en","tag-law","tag-manual","tag-perpetrator","tag-prevention-en","tag-receipt","tag-strategic-planning","tag-third-parties","ownarticle"],"acf":[],"cc_featured_image_caption":{"caption_text":"Thomas Schubert weiss, wie Compliance vom Kostentreiber zum Wettbewerbsvorteil wird.","source_text":"","source_url":""},"_links":{"self":[{"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/posts\/28244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/comments?post=28244"}],"version-history":[{"count":5,"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/posts\/28244\/revisions"}],"predecessor-version":[{"id":28575,"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/posts\/28244\/revisions\/28575"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/media\/28243"}],"wp:attachment":[{"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/media?parent=28244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/categories?post=28244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thebrokernews.ch\/en\/wp-json\/wp\/v2\/tags?post=28244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}