THE NEWS IN BRIEF
On July 16, 2026, the St. Lucie County Sheriff’s Office in Florida arrested three women in connection with an alleged seven-year scheme that funneled nearly $7 million out of a Fort Pierce-area business. According to CBS12 News and WQCS Public Radio, Laura Beth Grasso, 43, worked as the victim company’s bookkeeper and comptroller and allegedly used her position of trust and unsupervised administrative access to the company’s financial systems to bypass established accounts payable procedures, initiating unauthorized manual wire transfers to third parties. Investigators further allege Grasso worked with two accomplices, Sheri Lynn Harrs, 38, and Tina Marie Mejia, 55, to bypass payroll controls and issue duplicate payments benefiting the three of them, with detectives describing some of those payments as effectively hush money to keep Harrs and Mejia quiet about the scheme. The alleged proceeds went toward luxury vehicles, vacations, fine jewelry, designer accessories, and personal utility bills. Grasso faces charges of first-degree grand theft, organized fraud, money laundering, and conducting an enterprise through a pattern of racketeering activity; Harrs and Mejia face grand theft and racketeering charges. All three have been arrested, not convicted, and the Sheriff’s Office says the investigation remains active as detectives continue reviewing financial records.
THE CONSULTANT’S VERDICT
Seven years. The ACFE’s 2024 Report to the Nations puts the median duration of an occupational fraud scheme, from start to detection, at 12 months. If the allegations here hold up, this scheme ran roughly seven times longer than the typical case — not because the perpetrator was unusually clever, but because, as alleged, nobody independent of her was ever positioned to catch it. That is not a detection failure. It is a design failure.
Strip the allegations down to the control failure, and it is the same story I see in postmortem after postmortem: one person held both the ability to initiate a payment and the practical, unsupervised means to get it out the door, with no independent party reconciling what left the bank account against what accounts payable actually approved. A bookkeeper-comptroller role that combines transaction recording, wire initiation, and payroll administration in one set of hands is not a job description — as alleged, it is an open invitation, and it is disturbingly common in mid-sized businesses that never separated these duties as they grew.
Run the fraud triangle on what is alleged. Opportunity was structural: unsupervised administrative access to the financial systems, apparently with no maker-checker control on wire transfers and no independent bank reconciliation catching the pattern for years. Rationalization is the familiar story of a long-tenured, trusted employee who has watched the same unreconciled account for so long that the absence of a check starts to look like permission. Pressure, as with most of these cases, is speculative from the outside — but the alleged pattern of luxury vehicles, vacations, and jewelry is the classic signature of lifestyle spending that outpaces a known salary, which is precisely the kind of red flag that goes unnoticed when nobody is looking for it.
What makes this case worth studying beyond the dollar figure is the alleged recruitment of Harrs and Mejia through duplicate payroll payments described as hush money. That is fraud metastasizing: once a scheme like this is running, the perpetrator often needs company, and the price of that company shows up in the payroll ledger as duplicate payments, off-cycle runs, or payments to employees whose pay pattern suddenly changes. That is a detectable signal — if anyone is running analytics against payroll data rather than trusting that payroll, once set up, runs itself.
I see the equivalent structural gap constantly across the GCC, where a single finance manager or accountant in a family-owned or mid-market business is routinely trusted with bookkeeping, bank access, and payroll administration together, often because the owner sees a “trusted” long-serving employee and assumes trust is the control. The IIA Global Internal Audit Standards are explicit that internal audit’s role is to evaluate whether governance and control processes are operating as designed, not simply whether a policy document says segregation of duties exists on paper. A business that has a written accounts payable procedure but no one independently verifying that wire transfers match approved invoices does not have a control. It has a policy nobody is testing.
WHAT YOU SHOULD DO MONDAY MORNING
- Separate wire transfer initiation from approval and release. No single employee should be able to both create and release a wire transfer. Require a second, independent authorizer for every outbound wire above a low, board-approved threshold — and make sure that authorizer is not a direct report of the person initiating the transfer.
- Turn bank reconciliation into an independent, recurring control. Someone outside the bookkeeping or comptroller function — a controller reporting elsewhere, an outsourced accountant, or internal audit itself — should reconcile every outbound wire against the accounts payable approval trail on a monthly basis at minimum.
- Run payroll anomaly analytics quarterly. Screen for duplicate bank account numbers across employees, off-cycle or manual payroll runs, and pay changes that were not accompanied by an HR record. Duplicate payments to a small cluster of employees are one of the most detectable signatures of exactly this kind of scheme.
- Mandate uninterrupted leave for anyone with financial system access. Require at least two consecutive weeks of leave annually for bookkeeping, comptroller, and payroll roles, with duties fully covered by someone else during that window — a large share of long-running embezzlement schemes surface precisely when the perpetrator is forced to step away.
- Give staff a real, confidential channel to report concerns. If accomplices can be paid to stay quiet, it usually means no safe alternative existed. A functioning, independently monitored whistleblower line costs little and regularly surfaces exactly this kind of scheme years earlier than an audit would.
DON’T WAIT FOR THE HEADLINE TO BE ABOUT YOU
Right now, somewhere, one trusted employee holds the keys to bookkeeping, bank access, and payroll all at once — and leadership assumes years of loyal service is the control doing the work. It isn’t, until someone independent checks it. This exact scheme is running inside companies whose owners would tell you, with total confidence, that it couldn’t happen to them. If you want an honest, confidential look at whether your accounts payable and payroll controls would actually catch this before a detective does, message me directly on WhatsApp for an independent internal audit or fraud-risk health check — before a fraudster finds the gap first.







