The false choice between trust and control
After fraud, theft, an information leak or abuse of access, leaders may respond by increasing surveillance of everyone. More cameras, detailed activity monitoring and added approvals create a visible response.
Yet generalized monitoring can create more data without ensuring that the right signals are seen. It can erode trust, encourage people to bypass rules they consider unfair and turn compliance into appearance.
The real choice is not trust versus control. It is arbitrary control versus control that is understandable, focused and connected to a real risk. A healthy workplace can remain demanding: it explains what is protected, limits sensitive powers and reviews exceptions without treating every employee as a suspect.
Start with the processes that create opportunity
The ACFE’s 2024 global report, based on 1,921 cases, highlights the role of missing or overridden controls in occupational fraud. This points leaders toward work design before intrusive surveillance.
Where can one person request, approve and execute? Which permissions remain after a role change? Who can alter data without preserving a second trace? Which anomalies are known but never reconciled? These questions focus on the process, not personality.
- Role-based access reviewed after every change and removed promptly.
- Separation of duties for financial transactions, inventory, keys and sensitive authorization.
- Dual approval reserved for high-impact actions.
- Periodic reconciliation between events, systems and supporting evidence.
- Logging of material changes with alerts for defined exceptions.
- A confidential reporting channel supported by impartial review and protection from retaliation.
Supervise work without watching every person continuously
Effective supervision verifies outcomes, deviations and accountability. It does not assume that observing every movement creates better security.
Canadian privacy authorities note that workplace surveillance can affect dignity, autonomy, morale and trust. Their guidance emphasizes legitimate purpose, necessary collection, restricted access and clear communication.
A camera may be justified to protect a perimeter, dock, cash area or sensitive zone. It should not automatically become a permanent performance-monitoring tool. The distinction belongs in policy, notice and access permissions.
The question is not only “can we monitor?” It is “is this measure necessary, proportionate and capable of reducing the stated risk?”
Make controls predictable and investigations fair
A secret control is not always stronger. Publishing rules, checks and consequences can increase the perceived likelihood of detection while giving people a fair chance to comply.
When a signal appears, distinguish an anomaly, an error, a training gap and intentional misconduct. Preserve facts, limit file access and avoid premature conclusions. A credible process protects both the organization and the people involved.
- Explain controls and their purpose in accessible policies.
- Apply comparable thresholds to comparable situations.
- Separate reporting, analysis and decision roles when warranted.
- Keep only necessary information and destroy it under a documented rule.
- Provide a way to correct inaccurate information and challenge a decision.
Build a culture where concerns can be raised
Formal controls do not replace workplace culture. A team that fears retaliation, doubts that concerns will be handled or sees exceptions for influential people learns to remain silent.
Leadership must show that rules apply, good-faith reports receive serious attention and process errors improve the system. Consistency reduces rationalization and increases the chance that a deviation is found early.
Preventing internal crime without toxicity requires more discipline, not less: clear roles, limited powers, reliable evidence, proportionate monitoring and a fair process when facts must be examined.
References
Sources consulted
- Association of Certified Fraud Examiners (2024). Occupational Fraud 2024: A Report to the Nations.
- Office of the Privacy Commissioner of Canada. Privacy in the Workplace.
- Canadian privacy authorities (2023). Protecting Employee Privacy in the Modern Workplace.
This article provides general analysis. It does not replace an assessment of an organization’s specific context, obligations or facts.
