When Fraud Controls Are Challenged: Responding to Whistleblower Allegations
Federal prosecutors earlier this year reviewed whistleblower allegations concerning JPMorgan Chase’s handling of fraud cases and weaknesses in its anti-fraud controls, according to reporting published this week by The Wall Street Journal.
The allegations were made by Christy Lillie, the bank’s former head of scam prevention, and included claims concerning the classification of customer losses, reimbursement decisions and the handling of suspicious accounts.
JPMorgan has said the claims have no merit, that it investigated the concerns and found no evidence of wrongdoing or violations of law. Prosecutors have not accused the bank of wrongdoing, and it is unclear whether the federal review remains active.
Whatever the outcome of that matter, the reporting illustrates a wider corporate risk.
When an employee, compliance professional or whistleblower alleges that fraud controls are inadequate, the organization must determine what happened without prejudging either the allegation or the people involved.
That requires evidence preservation, clearly defined issues, independent fact-finding and disciplined reporting.
Start With the Allegation, Not the Conclusion
A whistleblower report may contain serious concerns, but an allegation is not the same as an established fact.
The first task is to define precisely what is being alleged.
Concerns may relate to:
- Failure to follow established fraud procedures
- Inadequate escalation of suspicious activity
- Incorrect classification of transactions
- Weaknesses in customer-authentication controls
- Failure to investigate identified warning signs
- Inconsistent reimbursement or loss decisions
- Management override of internal controls
- Retaliation or adverse treatment after concerns were raised
- Discrepancies between written policy and actual practice
These issues should be separated rather than investigated as one broad accusation.
A company may discover that some concerns are supported, others result from legitimate differences in interpretation and others cannot be established from the available evidence.
The purpose of an independent review is to distinguish between them.
Preserve Evidence Before It Disappears
Evidence preservation should begin as soon as a material allegation is received.
Relevant records may include:
- Emails and internal messaging
- Fraud-case files
- Escalation records
- Policies and procedural manuals
- Customer complaints
- Internal reports and dashboards
- Meeting minutes
- Compliance communications
- System logs
- Training records
- Relevant personnel files
- Previous internal-review findings
Preservation should be proportionate and coordinated with legal counsel where litigation, regulatory scrutiny or employment issues may follow.
Changes in personnel, routine document-retention systems and software updates can all affect the availability of evidence.
Organizations should therefore avoid waiting until every aspect of the allegation has been assessed before identifying records that may need to be retained.
Establish Who Knew What and When
Many internal-control investigations ultimately depend on chronology.
It may be necessary to establish:
- When the problem was first identified
- Who received the concern
- How it was escalated
- What evidence was available at the time
- Which decisions were made
- Who approved those decisions
- Whether recommendations were implemented
- Whether the same issue arose again
- Whether senior management or the board was informed
A detailed chronology helps distinguish later hindsight from what decision-makers actually knew at the time.
It can also identify gaps between formal escalation procedures and what occurred in practice.
Compare Written Policy With Actual Practice
A sophisticated policy manual does not prove that controls were functioning effectively.
An independent review may therefore compare:
- Written fraud procedures
- Actual case-handling records
- Escalation requirements
- Decision thresholds
- Training provided to relevant staff
- System capabilities
- Documented exceptions
- Management approvals
The objective is not simply to determine whether a policy existed.
It is to establish whether the organization applied it consistently and whether any identified weaknesses were recognised and addressed.
This distinction can be particularly important where regulators, auditors, outside counsel or boards need to assess the effectiveness of a control environment.
Separate Fraud Losses From Control Failures
A company experiencing fraud losses has not necessarily suffered a control failure.
Even sophisticated organizations cannot prevent every fraudulent transaction.
The relevant questions may instead include:
- Was the risk reasonably foreseeable?
- Were appropriate controls in place?
- Did staff follow them?
- Were known vulnerabilities escalated?
- Were previous incidents considered?
- Were suspicious patterns identified?
- Did commercial or operational pressure influence decision-making?
- Were exceptions properly documented?
A review should also distinguish between the conduct of an external fraudster and the organization’s internal response.
These are separate issues and may require different evidence.
Independence Can Matter
Internal teams may be capable of reviewing many concerns themselves.
However, an independent review may be appropriate where:
- Senior management is implicated
- The compliance or fraud function itself is criticised
- Previous internal findings are disputed
- A whistleblower alleges that concerns were suppressed
- Litigation is anticipated
- Regulators or law enforcement may become involved
- The board requires an independent factual record
- Multiple business units or jurisdictions are involved
Outside counsel may determine the appropriate legal structure for the review and whether privilege considerations apply.
Independent research and evidence analysis can then support counsel or corporate decision-makers with an objective factual record.
Conflict International USA’s Litigation Support Services are designed to support U.S. legal teams with targeted intelligence, evidence development and fact-finding in complex disputes.
Examine Relevant People and Third Parties Carefully
A control failure may involve more than internal procedures.
Depending on the allegation, relevant enquiries may concern:
- Employees and decision-makers
- Contractors
- Vendors
- Consultants
- Agents
- Payment recipients
- Connected companies
- Business partners
Research should remain tied to a defined objective.
For example, where an allegation concerns an undisclosed conflict of interest, enquiries may examine corporate affiliations, litigation history, professional relationships or publicly available business interests.
A connection does not establish misconduct.
Findings should distinguish confirmed facts, reasonable inferences and matters that remain unresolved.
For prospective relationships, acquisitions or appointments, Due Diligence Services USA can help identify integrity, litigation, regulatory and third-party risks before they develop into larger corporate issues.
Avoid Investigating to Reach a Predetermined Result
An internal investigation loses value if the expected conclusion is decided before the evidence is reviewed.
Organizations should avoid processes designed merely to:
- Validate an earlier management decision
- Discredit the whistleblower
- Establish that controls were adequate
- Find an individual to blame
- Produce a report supporting a predetermined legal position
The review should test the allegations against available evidence.
That may result in findings that support management, support the whistleblower, identify a different problem entirely or conclude that the evidence is insufficient.
A defensible process is more valuable than a convenient conclusion.
Reporting Should Separate Fact From Assessment
The final report should make clear:
- What allegation was examined
- Which evidence was reviewed
- What facts were established
- Which accounts conflict
- What remains unverified
- Which limitations affected the review
- What additional evidence may exist
- Which conclusions are factual and which are assessments
Investigators should not determine legal liability unless appropriately qualified to do so.
Employment law, regulatory exposure, disclosure obligations and potential litigation should be considered by the relevant legal advisers.
The investigation provides the factual foundation on which those decisions can be made.
When External Support May Be Appropriate
Conflict International USA supports corporations, law firms and professional advisers dealing with complex fraud allegations, internal disputes and litigation-related fact-finding.
Depending on the scope, work may include:
- Corporate and connected-party research
- Individual background and integrity enquiries
- Litigation and regulatory-record research
- Review and organization of documentary evidence
- Digital and open-source research
- Chronology preparation
- Third-party relationship analysis
- Cross-border corporate enquiries
- Clearly sourced reporting for legal or board review
Our role is evidence-led.
We do not assume that an allegation is true merely because it has been made, and we distinguish verified findings from allegations, possible connections and unresolved issues.
Discuss a Corporate Fraud or Whistleblower Matter
If your organization, board or legal team is responding to allegations concerning fraud controls, misconduct or disputed internal findings, Conflict International USA can assess what independent research and fact-finding may be proportionate.
Where possible, provide a concise summary of the allegation, the relevant individuals or entities and the principal questions that need to be resolved.
Complete the enquiry form below to request an initial assessment.