A small invoice flag uncovered years of theft.


A minor invoice discrepancy at a Nairobi financial firm led to the discovery of a multi-year scheme by an internal IS Manager. The fraud was hidden in small, fragmented rounding discrepancies that were invisible to standard accounting software. The client needed a forensic-grade IT audit to trace the leak to its source.
We executed a comprehensive transaction log audit, tracing every administrative action back to its originating session. By correlating database logs with network traffic patterns, we were able to identify the specific account and the unrotated access privileges that allowed the fraud to persist.
We then implemented the 912 access control framework, mandating multi-factor authentication (MFA) and automated privilege rotation for all privileged accounts, ensuring that no single individual has unchecked control over the financial engine.


The fraud was fully documented with forensic-grade evidence. The discovery cost the client almost nothing — it emerged as a byproduct of a standard IT audit engagement. The recovery was substantial. The client has since implemented the 912 access control and audit framework across all financial systems.
What changed, what risk was removed, and where to go next.
A minor invoice discrepancy exposed weak vendor and internal IT controls.
The suspicious pattern was escalated into a larger investigation and remediation path.
Unreviewed supplier, access, and infrastructure control drift.
Turn this result into a scoped conversation.
Most internal fraud isn't discovered by expensive forensic investigations. It's discovered by IT audits that happen to look in the right place. The 912 model includes periodic access reviews, privilege audits, and transaction log analysis as standard practice — not as an add-on.