The Answer in 60 Seconds

Discovery that an employee has committed material fraud against the SME triggers a defined operational and legal response. The Singapore framework runs through four threads: criminal investigation (the Penal Code 1871 (PC1871) covers criminal breach of trust at sections 405-409, cheating at sections 415-420; the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 (CDTOSCCBA1992) applies to proceeds of crime); civil recovery (against the employee and any complicit third parties); HR action (suspension, termination, evidence preservation); and insurance (the SME's Crime / Fidelity Guarantee cover responds to employee-dishonesty losses, subject to discovery-period and notification conditions). The first 24 hours are critical because evidence preservation, suspension protocols, and notification timing determine the strength of all four threads. This article sets out the 24-hour playbook by hour blocks, the documents to assemble, and the conduct-of-investigation questions the SME should be answering.

The Sourced Detail

Employee fraud is rarely discovered at the moment of commission; it is typically discovered weeks or months later through a discrepancy, an audit, a tip, or a routine reconciliation. The fraud loss has typically already crystallised by the time of discovery; the first 24 hours are about preserving the position and structuring the response.

The Singapore legal framework

Criminal breach of trust (CBT). Sections 405-409 of the Penal Code 1871 cover criminal breach of trust. Section 408 (CBT by clerk or servant) and section 409 (CBT by public servant, banker, merchant, factor) carry severe penalties. The employer (as the victim) may make a police report; the police investigation runs independently of the SME's civil recovery.

Cheating. Sections 415-420 of the Penal Code cover cheating offences, which may apply where the employee used deception to procure the loss.

Computer Misuse Act 1993. Where the employee used unauthorised access to computer systems to facilitate the fraud, section 3 (unauthorised access) and section 5 (unauthorised modification) apply.

Proceeds of crime. The CDTOSCCBA1992 regime applies to the proceeds of the fraud; tracing and confiscation may be available through the police investigation.

Civil claims. The SME may pursue civil recovery against the employee (debt, breach of fiduciary duty, conversion) and against third parties (recipients of the fraud proceeds, complicit parties, banks where applicable). The Limitation Act 1959 (LA1959) sets the time-bars; the fraud-postponement provisions can extend time where the fraud was concealed.

Crime / Fidelity Guarantee cover

The principal insurance cover is Crime or Fidelity Guarantee cover. Standard wordings respond to:

  • Employee dishonesty causing direct loss to the SME (theft of money, securities, or other property).
  • Forgery and alteration.
  • Computer crime (electronic theft using unauthorised access).
  • Funds-transfer fraud.
  • Money on premises / in transit.

Three policy conditions matter immediately:

Condition 1: Discovery period. The cover responds to losses discovered during the policy period; the underlying loss event may have been earlier. The discovery period typically extends beyond the policy expiry (commonly 60-90 days) to address late-detected losses.

Condition 2: Notification window. The insurer must be notified within a stated period of discovery. Late notification may prejudice the cover.

Condition 3: Cooperation and investigation. The insurer typically requires the SME to cooperate with the insurer's investigation, provide documents, and (where applicable) make a police report.

Hour 0-6: Containment and immediate response

Suspend access without alerting. Where the fraud is ongoing or where notice would allow the employee to destroy evidence or move funds, IT access, building access, and authority signatures are suspended quickly and quietly.

Preserve evidence. Documents, electronic records, email, financial transactions, audit logs, voice recordings - everything that may be relevant to the fraud is identified and preserved before remediation actions begin.

Engage external resources. External counsel (typically through the insurance policy's panel) is engaged. Forensic accountants may be engaged. The insurer's claims line is notified.

Internal escalation. CEO, CFO, internal counsel, head of HR are notified. The response team is convened.

Hour 6-12: Investigation kick-off

Forensic accounting. A scope of investigation is defined: which accounts, which periods, which counterparties. The forensic team begins work.

Employee interview / suspension. The employee is notified of the suspension. The interview, if conducted, is structured (with external counsel present) and recorded. The employee's denial / admission / silence is documented.

Police report consideration. The SME considers whether to make a police report. The criminal-process trade-offs are weighed (recovery prospects, business confidentiality, time involvement). Most insurers expect a police report to be made where the fraud is material.

Hour 12-24: Documentation and notification

Insurer formal notification. The Crime / Fidelity Guarantee insurer is formally notified in writing. The notification provides the policy reference, the date and circumstances of discovery, the preliminary scope, and the proposed investigation approach.

Bank notification. Where the fraud involves funds movement through specific accounts, the banks are notified. Banks may be able to freeze relevant accounts or trace funds.

Counterparty notification. Where third parties have received fraud proceeds, the SME (with legal advice) may notify them with a view to recovery.

HR action documentation. The suspension, the investigation steps, the employee's response - all documented contemporaneously.

Day 2 onward: Investigation, recovery, restoration

The 24-hour window establishes the response position. The subsequent weeks involve:

  • Continued forensic investigation.
  • Civil recovery proceedings if recovery prospects justify.
  • Criminal-process cooperation.
  • Insurance claim progression.
  • Process improvements to prevent recurrence.

Insurance covers that respond

Crime / Fidelity Guarantee. Principal cover.

Cyber. Where the fraud involved unauthorised access to computer systems or electronic funds-transfer fraud, cyber may respond in parallel.

D&O. Where the fraud reveals oversight failures, D&O may respond to directors' breach-of-duty claims (typically defensive, against shareholder or regulator claims).

Professional indemnity. Where the employee's fraud caused loss to professional clients, PI may respond to client claims.

Three structural lessons SMEs draw post-incident

1. Segregation of duties. Most material employee frauds are facilitated by a single person controlling end-to-end transaction approvals. Segregation breaks the pattern.

2. Routine reconciliation. Bank reconciliations, vendor reconciliations, customer reconciliations - performed by someone other than the transaction-processor.

3. Whistleblower channel. Many frauds are discovered through internal tips. A documented whistleblower channel (independent of the suspected fraudster) makes the tips actionable.

Common Mistakes / What Goes Wrong

  1. Alerting the employee before evidence is preserved.
  2. No external counsel engaged - the SME conducts the investigation in-house, prejudicing later claim positions.
  3. No police report despite material loss - insurer may dispute the cover position.
  4. Late notification of the insurer.
  5. Forensic investigation underscoped - subsequent extensions strain the cover position.
  6. No documentation of suspension steps - HR claims by the employee follow.
  7. Counterparty recovery attempted without legal advice.
  8. Bank freezes requested without legal basis.
  9. Process improvements not implemented - the same fraud pattern recurs.
  10. No post-claim debrief - lessons lost.

What This Means for Your Business

  1. Establish a fraud-response plan before any incident.
  2. Confirm Crime / Fidelity Guarantee cover is in force with appropriate limits.
  3. Build a pre-arranged panel of counsel and forensic accountants through the insurance policy.
  4. Operate segregation of duties as standard.
  5. Implement routine reconciliation independent of the transaction-processor.
  6. Establish a whistleblower channel.
  7. Train management on the response protocol.
  8. Conduct post-incident debrief to improve controls.

Questions to Ask Your Adviser

  1. For our Crime / Fidelity Guarantee cover, what is the limit and what is the discovery-period extension?
  2. For a fraud-event response, what is your support model and the panel of forensic accountants / counsel?
  3. For our segregation-of-duties profile, do you flag any structural weaknesses?
  4. For our cyber cover, how does it interact with Crime cover for funds-transfer fraud?
  5. For a whistleblower channel, what is the PDPA consideration?

Related Information

Published 22 May 2026. Source verified 22 May 2026. COVA is an introducer under MAS Notice FAA-N02. We do not recommend insurance products. We provide factual information sourced from primary regulators and route you to a licensed IFA who can match a policy to your specific situation.