top of page
Search

Nathan Mueller: A Real-Life Fraud Case Study—Learn Fraud Prevention From the Person Who Committed the Fraud

Live CPE Webinar • Monday, August 24, 2026 • 2 CPE Credits


Most fraud training is taught from the perspective of the auditor, investigator, regulator, or compliance professional.


This event is different.


On Monday, August 24, 2026, Corporate Compliance Seminars presents Nathan Mueller: A Real-Life Fraud Case Study, a two-hour ethics CPE program built around Mueller’s firsthand account of how he embezzled approximately $8.5 million over four years while working as an accountant at ING Reinsurance.


That creates an unusual learning opportunity.


Instead of asking only:

“How should auditors detect fraud?”

participants can also ask:

“How did the fraudster think?”
“What controls did he exploit?”
“What red flags were missed?”
“Why did the organization fail to detect the scheme sooner?”
“How did rationalization allow the fraud to continue?”

For internal auditors, external auditors, fraud examiners, compliance professionals, accountants, and finance leaders, those questions can be considerably more valuable than another theoretical fraud checklist.


Fraud Usually Requires More Than One Failure

Large occupational frauds rarely succeed because of one missing signature.


They typically involve a combination of:

  • Weak internal controls

  • Excessive access

  • Poor segregation of duties

  • Inadequate monitoring

  • Failure to investigate anomalies

  • Human trust

  • Behavioral red flags

  • Organizational complacency


Mueller's case demonstrates how those weaknesses can combine.


CCS's course examines how he exploited vulnerabilities within the organization and how warning signs went unnoticed while the fraud continued over several years.


That makes the case particularly relevant to auditors because it moves the discussion beyond:

“Was a control missing?”

toward:

“How did the entire control environment allow this to continue?”

Start With the Fraud Triangle

One of the most useful frameworks for analyzing occupational fraud remains the classic


Fraud Triangle:

Pressure


Opportunity


Rationalization


Mueller's story provides a real-life opportunity to examine all three.

Pressure

What pressures or motivations contributed to the behavior?

Opportunity

What access, system weaknesses, control gaps, or oversight failures made the scheme possible?

Rationalization

How does someone who knows an action is wrong gradually justify continuing it?


That last component is especially important.


Fraudsters do not necessarily wake up one morning thinking:

“Today I become a criminal.”

The progression may be much more gradual.


A boundary gets crossed.


Then rationalized.


Then crossed again.


Eventually abnormal behavior becomes normal.


That is why fraud training needs to include human behavior, not merely transaction testing.


The Most Important Question: How Did He Get Away With It for Four Years?

For an auditor, the amount—$8.5 million—is obviously significant.


But the more interesting fact may be the duration.


The scheme reportedly continued for approximately four years.


That should immediately generate audit questions:

  • Which controls should have identified the activity?

  • Were reconciliations being performed?

  • Who reviewed unusual transactions?

  • Were duties adequately segregated?

  • Was system access excessive?

  • Were unusual lifestyle indicators visible?

  • Did management rely too heavily on trust?

  • Were audit procedures predictable?

  • Were red flags investigated?


A fraud that continues for years is usually telling us something important about the control environment.


Trust Is Not an Internal Control

Organizations need trust.


But trust should not replace control.


A dangerous statement is:

“We've known this employee for years.”

Or:

“He's one of our best people.”

Or:

“She would never do something like that.”

Those may all be sincere statements.


They are not fraud controls.


A well-designed organization assumes that trusted employees still require:

  • Segregation of duties

  • Independent review

  • Access restrictions

  • Monitoring

  • Reconciliation


Internal controls should protect both the organization and honest employees by limiting the opportunity to commit or conceal wrongdoing.


Segregation of Duties Is a Fraud Defense

Fraud becomes easier when one employee controls too many pieces of a transaction.


Auditors should continually ask:

Can one person initiate, authorize, process, and conceal the transaction?

In a financial process, incompatible responsibilities might involve:

  • Creating a transaction

  • Approving it

  • Changing account information

  • Releasing payment

  • Reconciling the account


A strong segregation-of-duties framework forces multiple people to participate.


That does not make fraud impossible.


It makes fraud more difficult to execute and conceal.


System Access Can Create Opportunity

Modern fraud frequently depends upon technology.


An employee may possess access that allows them to:

  • Create transactions

  • Modify information

  • Change payment instructions

  • Post journal entries

  • Access bank information

  • Alter records


That means auditors should not evaluate only what someone's job description says they can do.


Ask:

What can the system actually allow them to do?

Those can be two completely different answers.


Auditors Need to Look for Behavioral Red Flags

CCS's program specifically emphasizes red flags that were missed during Mueller's tenure.


Behavioral red flags can include changes such as:

  • Lifestyle inconsistent with known income

  • Unusual defensiveness

  • Excessive control over responsibilities

  • Reluctance to take vacation

  • Resistance to sharing duties

  • Unusual relationships with vendors

  • Secrecy


None of these proves fraud.


That point matters.


A nice car is not audit evidence of embezzlement.


But behavioral indicators can provide additional context when combined with transactional anomalies or internal-control weaknesses.


Think of a red flag as:

A reason to ask another question.

Not:

Proof of guilt.

Continuous Monitoring Could Change the Detection Equation

Traditional auditing often looks backward.


The auditor selects samples from transactions that may be months old.


Fraud detection increasingly benefits from continuous or near-continuous analytics.


Organizations can potentially monitor for:

  • Unusual transactions

  • Duplicate payments

  • Weekend activity

  • Unusual journal entries

  • Transactions just below approval thresholds

  • Changes to vendor banking information

  • Payments to new accounts

  • High-risk user activity


The goal is not to accuse employees based on algorithms.


The objective is to identify transactions that deserve investigation.

CCS specifically incorporates continuous monitoring and stronger internal-control practices into the lessons drawn from Mueller's case.


Auditors Should Ask: How Would I Commit the Fraud?

This is one of the most useful fraud-planning questions.


Imagine you wanted to steal money from the process you are auditing.


How would you do it?


What access would you need?


Which control would stop you?


How could you bypass that control?


What evidence would your activity leave behind?


How could you conceal it?


This is not cynicism.


It is fraud-oriented risk assessment.


Auditors need to think about controls from the perspective of someone intentionally trying to defeat them.


Nathan Mueller's firsthand explanation gives attendees an unusual opportunity to understand exactly that perspective.


Why Were the Red Flags Missed?

A red flag has no value if nobody acts on it.


Organizations sometimes collect enormous amounts of information but fail at the next step.


The real process should be:


Red Flag

Investigation

Evidence

Escalation

Conclusion

Corrective Action


If warning signs exist but everyone assumes someone else is responsible for investigating them, risk falls through the cracks.


Human Behavior Matters as Much as the Control Matrix

Fraud prevention is not purely mechanical.


Human behavior matters.


Consider five behaviors auditors frequently encounter:


Denial

“We don't have a problem.”

Rationalization

“There is a good reason we do it this way.”

Defensiveness

“You're criticizing me.”

Fear

“What happens to me if I tell you the truth?”

Resistance to Change

“We've always done it this way.”

These behaviors can prevent an organization from recognizing fraud risk even when the technical warning signs exist.


Mueller's case is valuable precisely because it brings the human side of fraud into the discussion.


Rationalization Deserves Special Attention

Because rationalization is one component of the Fraud Triangle, auditors should learn to recognize the language used to normalize inappropriate behavior.


Examples include:

“I'm only borrowing it.”
“I'll put it back.”
“The company owes me.”
“Nobody will notice.”
“They treat employees unfairly.”
“I deserve this.”

Fraud prevention programs generally focus heavily on reducing opportunity.


That is appropriate because organizations can directly control many opportunities.


But ethics and organizational culture can also make rationalization more difficult.


Ethics Training Should Be About Decisions

Ethics becomes meaningful when the professional faces a difficult decision.


The CCS event explores ethical decision-making using Mueller's real-world experience rather than limiting the discussion to abstract rules.


The useful question becomes:

Where were the decision points where a different choice could have changed the outcome?

That is valuable for anyone working in:

  • Accounting

  • Internal Audit

  • External Audit

  • Finance

  • Compliance

  • Fraud prevention


People need to recognize the moment when a seemingly small exception becomes the beginning of something much larger.


Fraud Has Consequences Beyond the Dollar Loss

The financial loss is only part of the damage.


Occupational fraud can affect:

  • Careers

  • Families

  • Coworkers

  • Reputation

  • Employment

  • Organizational trust

  • Regulatory relationships

  • Control costs


CCS's program specifically includes Mueller's reflections on the personal and professional consequences of his actions and the lessons learned afterward.


That provides another dimension often missing from fraud training.


Fraud does not end when the accounting entry is corrected.


The Q&A May Be the Most Valuable Part

CCS includes an interactive question-and-answer session with Nathan Mueller.


That creates opportunities auditors rarely have.


Ask:

“Which control were you most worried would detect you?”
“Which red flags do you think auditors missed?”
“Did anyone ever ask a question that made you think you might be caught?”
“How did you rationalize continuing?”
“What would have stopped the fraud sooner?”
“What should internal auditors learn from your case?”

Those are questions a textbook cannot answer from firsthand experience.


AI Creates New Fraud Opportunities—and Detection Opportunities

The fraud environment is changing.


Artificial intelligence can potentially help organizations:

  • Analyze transactions

  • Detect anomalies

  • Identify unusual relationships

  • Review large data populations

  • Generate fraud-risk scenarios


But AI can also make it easier for fraudsters to:

  • Create convincing phishing communications

  • Impersonate executives

  • Generate fake supporting documents

  • Manipulate communications


That makes classic lessons about:

  • Segregation of duties

  • Independent verification

  • Professional skepticism

  • Fraud risk assessment

even more relevant.


Technology changes.


The need for effective controls does not.


Internal Audit Should Learn From Fraud That Happened Somewhere Else

One of the least expensive ways to improve your control environment is to study somebody else's fraud.


Ask:

Could this happen here?

Then:

Which control would stop it?

Then:

Have we tested that control?

That turns a fraud case study into a control self-assessment.


Nathan Mueller's case can therefore become much more than a fascinating story.


It can become a practical test of your own organization's fraud defenses.


What Participants Will Learn

The Nathan Mueller: A Real-Life Fraud Case Study event focuses on several core areas: how Mueller's fraud was executed, system and internal-control vulnerabilities, overlooked red flags, techniques for strengthening internal controls, continuous monitoring, ethical decision-making, and the personal and professional consequences of fraud.


Participants also have the opportunity to engage directly with Mueller during the Q&A session.


Who Should Attend?

The program is particularly relevant for professionals responsible for safeguarding organizational assets, including:

  • Internal Auditors

  • External Auditors

  • CPAs

  • Certified Fraud Examiners

  • Compliance Officers

  • Controllers

  • Finance professionals

  • Risk Managers

  • Audit Committee members

  • Executives


CCS describes the course as a Basic-level program requiring no prerequisites or advance preparation.


The Bottom Line

Most fraud courses teach you what the fraudster might do.


This course gives you the opportunity to hear from someone who actually did it.


Nathan Mueller's $8.5 million embezzlement provides a powerful case study in:

  • Opportunity.

  • Rationalization.

  • Weak internal controls.

  • Missed red flags.

  • Human behavior.

  • Ethical decision-making.

  • The consequences of fraud.


For auditors, the most important question is not simply:

“How did Nathan Mueller steal $8.5 million?”

The more valuable question is:

“Why did the organization's controls allow him to continue for four years—and could the same kind of weakness exist in our organization?”

That is the question Corporate Compliance Seminars' Nathan Mueller: A Real-Life Fraud Case Study is designed to help professionals answer.


Join CCS on Monday, August 24, 2026, for two hours of ethics CPE built around an opportunity most fraud courses cannot provide: learning about occupational fraud directly from the person who committed it.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page