THE NEWS IN BRIEF
On July 14, 2026, Michael Darcy, 49, of Hinsdale, New Hampshire, pleaded guilty to five counts of bank fraud for embezzling approximately $344,874 from his employer, according to a press release from IRS Criminal Investigation and U.S. Attorney Erin Creegan. Darcy served as operations manager at the Phelps Company and, according to the indictment and reporting by New Hampshire Public Radio, used his access to the company checkbook to forge his employer’s signature on dozens of unauthorized checks between December 2019 and December 2024, concealing the payments under false headings in the company’s own accounting records. Court filings state that roughly $142,000 of the stolen funds went toward pornography and adult websites. Darcy, notably, spent nearly a decade as a Hinsdale selectman, including a term as board chair, before his final term concluded in 2020. He faces up to 30 years in prison on each count; U.S. District Judge Steven J. McAuliffe has scheduled sentencing for October 28, 2026.
THE CONSULTANT’S VERDICT
Five years. That is how long this ran before anyone caught it — against a backdrop where the ACFE’s most recent Report to the Nations puts the median occupational fraud scheme at roughly 12 months from start to detection. Five years is not a story about a clever fraudster. It is a story about a checkbook nobody was watching and a set of accounting records nobody was cross-checking against the bank.
Strip away the salacious spending detail and what is left is a textbook single-point-of-failure. An operations manager had unsupervised access to the company checkbook, the authority to sign the owner’s name to checks, and — critically — the ability to record those same transactions in the company’s books under whatever heading he chose. That is three control functions living in one person: custody of the payment instrument, authorization, and recordkeeping. Any one of the three, held independently by someone else, likely stops this scheme inside a year, not five.
Run the fraud triangle on the facts as alleged. Opportunity was structural and total: check-signing authority with no dual control, and accounting entries that were never reconciled against actual bank activity by anyone outside Darcy’s own function. Rationalization likely built over years of an unchallenged pattern — a decade of community standing as an elected selectman probably reinforced, in his own mind and everyone else’s, the assumption that he was the last person who needed watching. Pressure is speculative from the outside, but a five-figure-a-year pattern of spending on adult content is exactly the kind of compulsive, hidden drain on personal finances that periodic lifestyle or expense-pattern reviews are designed to surface — if anyone is running them.
This is a small, closely held business, which is precisely where the IIA Global Internal Audit Standards’ emphasis on evaluating whether controls actually operate as designed — not merely whether they exist on paper — matters most. Smaller organizations routinely have an accounts-payable “process” that consists of trusting one long-tenured person completely. In the GCC, I see the identical structural gap in family businesses and mid-market firms constantly: an owner who long ago handed the checkbook, the ledger, and the bank relationship to one trusted finance employee and never revisited that decision as the business grew. Trust is not a control. A control is something that operates whether or not the person being controlled is trustworthy — and it has to be tested, not assumed.
WHAT YOU SHOULD DO MONDAY MORNING
- End single-signer check authority immediately. No one person should be able to both write and sign a company check, physical or electronic, above a low, board-set threshold. Require a second signatory who reports independently of the person initiating payment.
- Move bank reconciliation outside the payables function. The person who enters transactions into the books should never be the same person reconciling the bank statement against those entries. If your business is too small for a second finance hire, outsource monthly reconciliation to an external accountant — it is cheap insurance against exactly this scheme.
- Audit the chart of accounts for vague or catch-all headings. Darcy allegedly hid payments under false headings in the books. Pull a sample of general ledger entries quarterly and trace anything booked to a miscellaneous, suspense, or generically labeled account back to source documentation.
- Independently verify signatures against the bank’s signature card periodically. Most banks will confirm authorized signatories on request. A yearly check that the names on file match your actual approved signers catches forged-signature schemes that internal review alone will miss.
- Watch for the “long-tenured, unquestioned” employee as a risk factor, not a comfort. Longevity and community standing are not evidence of integrity — they are, statistically, correlated with larger fraud losses because tenure buys unchecked access. Rotate financial-access duties or mandate uninterrupted leave for anyone holding check-signing or ledger authority.
DON’T WAIT FOR THE HEADLINE TO BE ABOUT YOU
Right now, some company’s most trusted employee holds the checkbook, the ledger, and the bank relationship — all three, unchecked, because nobody ever thought to ask what would stop them if they decided not to be trustworthy for a single afternoon. This exact scheme is running today inside businesses whose owners would swear on their reputation that it couldn’t happen to them. If you want an honest, confidential look at whether your payables and reconciliation controls would actually catch this before five years pass, message me directly on WhatsApp for an independent internal audit or fraud-risk health check — before a fraudster finds the gap first.






