ERP Fraud Files, Part 13: More Than 245 Transfers to Accounts the Senior Accountant Controlled

Mandy Urban made more than 245 transfers out of her employer's bank accounts and into accounts she controlled, $1,115,344.73 in all. She was a senior staff accountant at a Charlotte company from January 2019 to June 2022. She pleaded guilty to wire fraud in March 2024 and was sentenced in February 2026 to 41 months in prison followed by two years of supervised release.

What happened

Her job covered a lot of ground. According to the U.S. Attorney's Office, she maintained the company's general ledger and prepared its financial statements. She also reconciled the accounts, bank statements included.

Divide $1,115,344.73 by 245 and you get about $4,552. The release says "more than" 245 transfers, so the real average sits lower. Then, in the release's words, she "falsified the company's books and records to conceal the scheme."

The release also lists two Florida convictions. In 2015 she was sentenced to five years of supervised probation for grand theft of about $135,000. In June 2022 she was sentenced to two years in prison for a different scheme to defraud. June 2022 is also the month her employment at the Charlotte company ends in the release's timeline. It does not say how that employment ended, or whether the two are connected.

Why the gap existed

In a company where the controls work, the ledger, the financial statements built from it, and the bank reconciliation check one another. Here one person held all of them. The release doesn't mention anyone else reviewing her work.

A bank transfer to an account that belongs to no vendor and no employee is a detectable event, provided something compares outgoing destinations to the master files. More than 245 of them is a pattern, however small each one was.

The 2015 conviction predates her start date by four years. It was public record on her first day. The release doesn't say whether anyone looked.

Controls that would have caught it

Keep bank reconciliation away from whoever posts to the ledger. The person who reconciles the cash accounts should not be able to post to them, and should work from statements that come straight from the bank. Preparing the financial statements is a different job again, which belongs to a different person where headcount allows and to an outside reviewer where it doesn't.

Match every outgoing transfer destination to the master files. A transfer needs a payee that exists in the vendor or employee records, with the account approved by someone other than the person releasing the payment. A new destination account should trigger a notification, not pass as a quiet setup step.

Screen finance hires, and rescreen them, with the results held outside finance. Anyone with bank access or ledger rights gets a background check before the first day and again at set intervals, within whatever the law allows where the company operates. The results go to HR or ownership.

An AI prompt example for ERP fraud detection

This case calls for one query about destinations and one about who did what. Against an ERP's cash management and general ledger modules, an auditor could run something like:

"List all outgoing bank transfers over the last four years where the destination account does not match a bank account on any vendor, employee, or customer record."

A second query goes after the overlap in duties:

"List every user who both posted journal entries to a cash account and completed the bank reconciliation for that same account, by period."

Neither query needs a suspect. Both need the master files to be current, which is its own project.

The pattern for this series

Parts 5, 7, 10 and 12 each had one person who kept the books and could edit them. Urban makes five. What is new here is a theft conviction on record four years before the first day of work. Part 12 raised the question of whether anyone knew about an earlier theft, and this release is just as quiet.

Source disclaimer

The case details in this article are drawn from a press release published by the U.S. Attorney's Office for the Western District of North Carolina, a public government source. All facts, figures, and quotations describing the case are sourced from that release. The analysis of the control gap, the proposed detection controls, and the AI prompt examples are original commentary and are not part of the source material.

References

United States Attorney's Office, Western District of North Carolina. Press release on the sentencing of Mandy Deann Urban for embezzling from her employer, February 2026. https://www.justice.gov/usao-wdnc/pr/twice-convicted-accountant-sentenced-embezzling-more-11-million-employer


More of my writing lives at A Tinkerers Notebook.

My book Gamifying the Enterprise: Game Mechanics for Continuous Proficiency is on Amazon. All my books are on my Amazon author page.

The AD&D365 configuration guides are at adnd365.com/start.

Connect with me on LinkedIn.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.