Between 2012 and 2024, a county treasurer in Arizona, United States, misappropriated approximately USD 38.7 million in public funds through 187 unauthorized wire transfers. She was sentenced in June 2025 following a federal prosecution. The mechanism was not technically sophisticated: the treasurer used the authentication credentials of a subordinate employee to complete both stages of a required two-person wire transfer approval process, effectively eliminating the independent review the control was designed to provide.
This case is examined here because the control failure was not a matter of missing policy. A dual-authorization requirement existed and was documented. The failure occurred at the point where policy was expected to be enforced by the system, and was not. This is precisely the class of control that IT General Controls (ITGC) testing is designed to evaluate.
1. Control Design and Observed Practice
The organization’s stated control required that no single individual could both initiate and approve a wire transfer. As implemented, this requirement relied on procedural separation of roles rather than a system-level restriction preventing one authenticated identity from completing both actions. Court documents indicate the treasurer used a subordinate’s security token to satisfy the second-approval requirement, allowing her to complete the full transaction cycle unilaterally.
2. Detection
The scheme was ultimately identified through a routine internal audit, which surfaced discrepancies that led to a federal investigation. This detail is material to the analysis: the relevant control category — independent review and reconciliation — did function, but only after a decade and a scale of loss that a more rigorous, continuously tested control environment would be expected to have limited substantially earlier.
3. Applicable Control Recommendations
The following control measures, tested as part of a standard ITGC review, directly address the failure mode identified in this case:
Four Controls That Would Have Closed This Faster
01 System-Enforced Dual Authorization
The system itself refuses to let one credential complete both the request and the approval steps.
02 Credential & Token Management
Access patterns are tested for tokens used outside their assigned holder’s normal device or location.
03 Anomaly Detection on Approvals
Routine analytics flag one person repeatedly approving transfers to the same new payees.
04 Independent Reconciliation
Cash and investment reports are verified against source bank data, not self-prepared spreadsheets.
4. Broader Applicability
This exposure is not specific to public-sector treasury functions. Any organization operating a dual-approval requirement for payments, disbursements, or transfers carries equivalent risk if that requirement is enforced procedurally rather than at the system level. A control’s existence in policy documentation is not evidence of its operation. Verification requires testing whether the control can be circumvented under realistic conditions, including credential sharing, delegated access, and emergency-override scenarios.
About This Series
This is the first in a series of case analyses published by PKF Thailand’s IT Assurance & Advisory practice, examining documented control failures and mapping them to specific, testable ITGC procedures. The practice performs independent reviews of access management, segregation of duties, change management, and system-level financial controls, designed to complement statutory audit and IT risk advisory engagements.
Organizations seeking to assess whether their dual-authorization controls are enforced at the system level, rather than assumed to be, are welcome to contact PKF Thailand’s IT Assurance & Advisory practice.
Source: U.S. Attorney’s Office, District of Arizona — press release, June 24, 2025
#ITAssurance #ITGC #InternalControls #AccessManagement #FraudPrevention