Skip to main content
Should Finance Track Who Touches Loan Data?Financial & Accounting Fraud
6 min readFor Compliance Training Managers

Should Finance Track Who Touches Loan Data?

These questions landed in my inbox after the SEC charged three Tricolor executives with orchestrating a scheme that double-pledged subprime auto loans and misled investors about collateral quality. The charges describe years of manipulated metrics and concealed liens that ultimately left more than $945 million outstanding when the company filed for bankruptcy in September 2025.

The questions come from compliance managers, finance leaders, and audit teams trying to figure out what their controls actually need to do. They're practical, direct, and worth answering clearly.

Can We Prevent Executives from Manipulating Financial Data?

No single control stops a CEO and CFO working together to commit fraud. That's the hard truth. But you can make it much harder and create early warning signals.

Start with segregation of duties in your financial reporting systems. If the same person who marks a loan as current also certifies it for securitization, you've built a single point of failure. Separate data entry from approval. Separate approval from certification to investors.

Add automated exception reports that flag unusual patterns: loans moving from delinquent to current without payment activity, collateral pledged to multiple facilities within short timeframes, or manual overrides to loan status fields. These reports should go to someone outside the finance leadership chain, like internal audit or the audit committee.

The goal isn't to catch every possible scheme. It's to make fraud require more people, more steps, and more visible anomalies. That increases the chance someone notices and speaks up before the damage compounds.

Training to Recognize When "Making the Numbers Work" Becomes Fraud

Focus your training on the moment of rationalization. People don't usually wake up planning to commit securities fraud. They start by telling themselves a story: "This loan will cure next month anyway, so marking it current now is just a timing issue." "We'll fix the double pledge before anyone notices." "The business is fundamentally sound, so these adjustments just reflect reality better."

Use scenarios that show the progression. Walk through a case where someone manually overrides a delinquency flag "just this once" to meet a securitization deadline, then does it again the next quarter, then starts doing it systematically. Ask learners: at what point does this become fraud? The answer matters less than the discussion it prompts.

Teach the specific red lines in your industry. For asset-backed securities, that includes representing collateral as unencumbered when it's pledged elsewhere, manipulating loan performance metrics to meet eligibility criteria, and making material misrepresentations about financial health to investors. These aren't gray areas. They're violations of the antifraud provisions of the Securities Act of 1933 and the Securities Exchange Act of 1934.

Give people language to push back: "I'm not comfortable certifying this without documentation." "This adjustment needs a second review before we include it in investor materials." Make it clear that raising concerns is expected, not risky.

What Should the Audit Committee Focus On?

Audit committees should ask about the controls around data that goes to investors, not just the controls around financial statements. The Tricolor case involved misrepresentations in ABS offering materials and investor meetings, which may not flow through the same review process as a 10-K.

Specific questions to ask management:

  • Who can manually override loan status or performance metrics in our systems, and do we track those overrides?
  • How do we verify that collateral in securitization pools isn't pledged elsewhere?
  • What reconciliation happens between our loan database and what we certify to underwriters?
  • When did we last test whether our controls would detect double pledging or metric manipulation?

Request exception reports quarterly: loans with manual status changes, collateral pledged to multiple facilities, and any differences between automated system outputs and what got reported to investors.

If management says "we trust our CFO" or "our systems prevent that," that's not an answer. You need to see the control, not hear about the person.

Do Employees Report Financial Fraud?

Some do, some don't. The ones who do need three things: a clear channel, confidence it won't blow back on them, and belief that someone will actually investigate.

Your speak-up program should explicitly cover financial reporting concerns and make clear that employees can report to internal audit, the audit committee, or external hotlines, not just their manager. If the CFO is the problem, reporting to the CFO's team won't work.

Train managers and finance staff on what anti-retaliation safeguards actually mean. It's not just "we won't fire you." It includes protection from reassignment, exclusion from meetings, or subtle marginalization. People notice when a colleague raises a concern and then stops getting invited to key discussions.

Investigate every report about data manipulation, even if it seems small. The loan analyst who notices that delinquent loans keep getting marked current before securitization deadlines might be seeing the early stage of a scheme. If you dismiss it as a timing quirk, you've told that person not to bother reporting next time.

How Specific Should Our Policies Be?

Very specific. Don't rely on "act with integrity" or "ensure accurate reporting." Those are too abstract when someone is under pressure to hit a funding target.

Your policy should explicitly prohibit:

  • Manually changing loan status, payment history, or collateral values without documented justification and supervisory approval
  • Representing assets as unencumbered when they're pledged as collateral elsewhere
  • Including ineligible loans in securitization pools or misrepresenting loan performance to meet eligibility criteria
  • Making material misrepresentations about financial condition to investors, lenders, or underwriters

Spell out the approval chain for any manual adjustments to data that goes to external parties. Require dual sign-off. Require a written rationale that gets retained.

This level of specificity helps in two ways: it removes ambiguity for people trying to do the right thing, and it removes the "I didn't know that wasn't allowed" defense for people who aren't.

Should We Track Who Accessed or Changed Records Related to Investor Disclosures?

Yes, and you should be auditing those access logs. Modern financial systems can log every query, every edit, and every export. If you're not capturing that data, start. If you're capturing it but never reviewing it, you're wasting the control.

Set up automated alerts for unusual access patterns: finance staff querying loan data outside business hours before a securitization closing, bulk exports of collateral records, or multiple failed login attempts to systems containing investor-facing data.

Review access logs as part of your pre-disclosure process. Before you file offering materials or meet with investors, someone outside the finance team should verify that the data in those materials matches your source systems and that any manual adjustments were properly approved.

This isn't about assuming your team is dishonest. It's about creating an audit trail that protects honest employees and makes it harder for dishonest ones to operate without leaving evidence.

Next Steps

If you're responsible for financial controls or compliance training, start by mapping the path your data takes from origination to investor disclosure. Identify every point where someone can manually intervene. Ask whether you'd detect it if they did.

Review your tone from leadership. If executives talk about "doing whatever it takes" to close a funding round or meet a liquidity target, that's a cultural red flag. Pair it with weak controls, and you've created conditions for rationalized fraud.

Build relationships between compliance, internal audit, and your speak-up program. The people who see early warning signs are often junior analysts or operations staff who won't report unless they trust the process and the people running it.

The Tricolor case is a reminder that fraud at scale requires systems that fail and people who stay silent. Fix the systems. Protect the people who speak up.

You Might Also Like