top of page

Trust Is Not an Internal Control: Fraud Lessons Every Supervisory Committee Should Sit With David Reed

  • 4 days ago
  • 3 min read

When a major credit union fraud makes headlines, the instinct is to treat it as someone else’s catastrophe — a failure so large it couldn’t happen at your shop. Credit union attorney David Reed takes the opposite view. As he told me on a recent episode of With Flying Colors, it would be almost criminal not to use a moment like this to ask the harder question: would we catch that here?


Reed knows the terrain. A former general counsel, he also spent ten years on a supervisory committee, several as its chair. When the alleged fraud at Jackson Area Federal Credit Union surfaced — with all allegations drawn from NCUA’s amended lawsuit — he was in the middle of teaching a two-day national supervisory committee school. The case became a live teaching tool, and the lessons travel well beyond one institution.


His starting point is a phrase worth taping to every boardroom wall: trust is not an internal control. Fraud rarely unravels on regulations or best practices alone. It unravels on a human moment — when someone has to look at a well-liked, long-serving colleague and consider that something is wrong. “I’ve known them for years” is the sentiment that lets it continue. Internal controls exist precisely so that judgment doesn’t rest on affection.

That leads to the uncomfortable arithmetic of where fraud actually lives. Statistically, at credit unions below a couple hundred million dollars, the greatest exposure is internal — the people with the most access, who know what an examiner or auditor looks for, know when they’re coming, and package the very documents under review. Yet these are the accounts least likely to get an independent look. Reed is blunt about the misallocation of effort: committees proudly run pop teller audits, but a teller’s drawer is counted before and after a shift. The real risk sits higher up.


He has a name for the failure mode: the clipboard audit. A supervisory committee tells him it conducts random loan reviews. He asks how. The CEO selected the loans, filled out the initial worksheet, and walked them through it in a meeting room. They believed they’d been thorough. Then Reed asks whether anyone reviewed the CEO’s own account — and is met with a blank “what about it?” When the person being overseen sets the scope, highlights the pages, and supplies the narrative, oversight has quietly become a guided tour.

The antidote is independence, and it doesn’t require heroics. Even a volume-only review of senior-executive accounts — not a forensic dig, just a look at the flow — can be done remotely, without asking the executive to unblock a hold or print their own statements. In the Jackson Area matter, Reed notes, a substantial sum allegedly moved directly through the CEO’s and her husband’s own accounts. Volume alone should have prompted a question.


Reed also challenges a number many credit unions treat as settled: the $500 million threshold for a full CPA opinion audit. He’d lower it to $250 million. His reasoning is that technology has erased the gap that once justified the line. A $100 million credit union today offers Zelle, Apple Pay, account-to-account transfers, even commercial accounts — nearly the full product load of a large institution, and nearly the full fraud exposure. Many of his clients below $500 million already obtain CPA audits voluntarily, because they add accountability and assurance. My own rule of thumb: if you’re at $450 million, $425 million, or $350 million, and not getting an opinion audit, reconsider. You can afford it, and it’s worth every penny. Better still, audit scope works like a cafeteria plan — a targeted review of insider accounts can simply be added.


What ties it together is Reed’s closing theme, and it’s the most actionable takeaway of all. Most credit unions already possess the tools, the processes, and often the results they need. BSA systems flag unusual activity. Analytics surface patterns. Audit plans can be built without hiring an internal auditor. The failure is rarely the absence of a tool — it’s that no one activated it, or no one reviewed the output. Whether the goal is catching fraud or reaching a member before they fall silent on a past-due balance, the question is the same: you have the information. Are you looking at it?

You can hear the full conversation with David Reed of Reed & Jolly on With Flying Colors, and reach David directly at david@reedandjolly.com.

 
 
 
bottom of page