There's a real difference between catching fraud when it happens and managing the risk of it happening at all. Most Tanzanian businesses we talk to are doing the first one, reactively, after a discrepancy forces the issue. Very few have anything that looks like an actual program: a system for figuring out where the business is exposed, controls sized to match that exposure, and a plan for what happens the moment something looks wrong.
That gap is understandable. Fraud risk management sounds like something for a bank or a multinational with a compliance department, not a distributor with fifteen staff or a family-run manufacturing business. It isn't, though. The core of it scales down fine. What follows is how to build it for a business that doesn't have a compliance team, just an owner or manager who wants to stop finding out about problems after the money is already gone.
None of this requires new software or a big budget. It requires deciding, on purpose, where the business is exposed and what happens at each of those points, rather than leaving it to whoever happens to notice something eventually.
Start with an honest risk assessment
Generic fraud checklists tend to miss what actually matters for your specific business. A risk assessment that means anything starts with a genuinely honest question: where, specifically, could someone in this business steal from it or manipulate it, and who is positioned to do that?
Walk through the money and stock flows one at a time. Who approves purchases? Who receives goods and checks them against the order? Who handles cash from sales? Who has the authority to write off inventory as damaged or expired? At each step, ask what would happen if the person in that role decided to abuse it, and whether anyone else would notice.
This exercise usually surfaces a handful of genuinely exposed points rather than a hundred theoretical ones. In a retail or FMCG business, that's often stock write-offs and supplier kickbacks. In a services business, it's more likely to be expense claims and vendor selection. In a business working through agents, it's frequently what happens between the warehouse and the customer, a stretch that's hard to observe directly. Our risk surveys and loss prevention work usually starts with exactly this kind of walkthrough.
The point isn't to list every possible fraud scenario. It's to know, specifically, which two or three points in your business carry the most exposure, so the next steps actually target something real instead of applying generic advice evenly across the whole operation.
Design controls sized to your actual risk
Controls that get copied from a generic template rarely fit. A five-person business doesn't need the approval chain of a two-hundred-person one, and forcing it in usually just gets ignored within a month because it slows everything down for no real benefit.
Instead, size each control to the specific exposure it's addressing. If cash handling is the risk, someone other than the cashier should be doing the daily reconciliation, even if that's just the owner spending fifteen minutes checking the till against the receipts. If procurement is the risk, purchases above a set amount need a second signature, and that threshold should be low enough to actually matter for your business's typical transaction size, not copied from a template built for a much bigger company.
Segregation of duties is the single most useful principle here, and it doesn't require more staff to implement, just a different split of the same staff you already have. The person who requests a purchase shouldn't be the same person who approves it. The person who approves payment shouldn't be the same person who reconciles the bank statement afterward. Even with three or four people total, there's almost always a way to split these roles so no single person controls a process from end to end.
We've reviewed cases where a single control, just requiring a second signature above a fairly modest threshold, would have stopped a loss that ran for over a year before anyone noticed. It's rarely the absence of any controls at all. It's usually one specific gap that someone eventually found and used, the same pattern we cover in our guide on detecting and preventing business fraud in Tanzania.
Build monitoring into how the business actually runs
A control that exists on paper but never gets checked isn't really a control. Monitoring is what makes the difference, and it needs an owner and a rhythm, not just a policy document sitting in a drawer.
Assign someone specific to own this, even in a small business. It doesn't need to be a full-time role. It needs to be someone whose job includes actually looking at reconciliations, approval logs, and inventory variance on a set schedule, and who has the standing to ask uncomfortable questions when something doesn't add up.
Set a cadence and stick to it. Weekly for cash and inventory reconciliation in a business where that turns over fast. Monthly for vendor payment reviews and expense claims. Quarterly for a broader look at access permissions, who can approve what, and whether that list still matches who's actually in those roles today. Our guide on how to catch fraud early goes deeper into the day-to-day habits this rhythm should actually include.
Vary it occasionally, too. A surprise stock count on a random Tuesday tells you more than a scheduled one everyone's ready for. Predictable monitoring gets worked around eventually. Unpredictable monitoring is harder to plan against.
None of this needs to feel adversarial toward staff. Most employees have nothing to hide and won't mind a consistent, fair check applied to everyone equally. The problem only shows up when monitoring is inconsistent, applied to some people and not others, or so rare that a year can pass between real checks.
Have a response plan ready before you need one
This is the part almost every business skips, and it's exactly the part that determines whether a suspected fraud gets handled well or turns into a mess. Deciding how to respond in the moment, while already stressed and uncertain, tends to go badly.
Decide in advance who gets told first when something looks wrong, and keep that list short. The fewer people who know before there's a plan, the less chance of the situation leaking to the person involved before you're ready to act. Decide who documents what's been noticed, and how, dates, amounts, specific transactions, not vague impressions.
Decide, ahead of time, at what point this moves from an internal concern to something that needs outside help, an accountant to verify the numbers, an investigator to establish who's responsible and gather evidence, or legal counsel if it's likely to end in dismissal or prosecution. Waiting until you're in the middle of a live situation to figure out who to call wastes time you often don't have, since evidence and access both get harder to secure the longer a suspected employee remains unaware they're under scrutiny. Our guide on what to do once you actually suspect fraud walks through this decision in more detail.
A plan doesn't need to be complicated. A single page naming who's involved, what gets documented, and at what point outside help gets brought in is enough to prevent the panic-and-improvise response that makes most fraud cases harder to resolve than they needed to be.
Treat it as ongoing, not a one-time project
Risk changes as the business changes. A new product line, a new region, a new agent network, or simply growth, all shift where the exposure sits. A risk assessment done two years ago probably doesn't reflect where the business actually is today.
Revisit the assessment at least once a year, and any time something significant changes in how the business operates. Bring in an outside perspective periodically too, an external investigator or auditor who isn't embedded in daily operations tends to spot gaps that become invisible to people who work inside the system every day. Our guide on what to expect from a private investigator covers what that kind of periodic outside review actually looks like and costs.
It's also worth looking at risk transfer, not just prevention. Fidelity insurance and crime cover, which pay out on losses from employee dishonesty, exist specifically for this. They don't replace good controls, but they're a reasonable backstop for the risk that slips through anyway, and worth discussing with whoever handles your business insurance if you don't already have this in place.
Think of the whole program the same way you'd think of stock control or cash management, something that needs regular attention, not a project you finish once and file away. Businesses that treat it that way tend to catch problems while they're still small and cheap to fix.
Frequently Asked Questions
Prevention is the day-to-day habits, reconciling regularly, checking invoices, watching for red flags. Risk management is the broader system those habits sit inside: a formal assessment of where you're exposed, controls designed to match that exposure, ongoing monitoring with a clear owner, and a response plan ready before it's needed. Prevention is what you do. Risk management is deciding what to do and why, on purpose, rather than by instinct.
The word "formal" makes it sound bigger than it needs to be. A one-page risk assessment, a clear split of who requests, approves, and pays, a named person who owns monitoring, and a simple response plan cover most of what matters, even for a business with fewer than ten staff. The size of the documentation should match the size of the business. The presence of a program shouldn't be optional just because the business is small.
Usually the owner or a senior manager who isn't directly handling the day-to-day transactions being monitored. Whoever it is needs enough standing in the business to ask hard questions without it feeling like an accusation, and enough consistency that monitoring actually happens on schedule rather than getting pushed aside when things get busy.
Fidelity and crime insurance policies are built for exactly this, covering losses from employee dishonesty or theft. It's worth checking whether your existing business insurance includes this, since it's sometimes an add-on rather than a default. It's a backstop, not a substitute for actually preventing the loss in the first place.
At least once a year as a baseline, plus any time something material changes, a new product line, a new market, significant growth, or a new way of working with agents or distributors. An assessment built for how the business operated two years ago often misses exactly where the current exposure sits.
Start with the risk assessment, the honest walkthrough of who touches money and stock at each step. It takes an afternoon, not a consultant's engagement, and it tells you exactly where to focus first instead of trying to fix everything at once. From there, the segregation of duties and approval thresholds are usually the fastest wins.
A fraud risk management program doesn't need to be complicated to work. It needs an honest assessment, controls that actually match the risk, someone who checks consistently, and a plan for the day something goes wrong. FP Adjusters helps Tanzanian businesses build exactly this, from the initial risk assessment through to investigating a case once something's already been flagged.
Ready to Build an Actual Program?
Tell FP Adjusters about your business, and we will help you map where the real exposure sits and what controls would actually fit it.
Talk to an Investigator