Skip to main content
Category: Predicate Offenses

Embezzlement

Also known as: Misappropriation of entrusted funds
Simply put

Embezzlement is a type of financial crime in which a person who has been lawfully entrusted with money or property, often an employee, officer, or agent, dishonestly takes it for their own use. It differs from ordinary theft because the person already had lawful access to or control over the assets before wrongfully appropriating them. It is most commonly associated with the misappropriation of money from a business or employer.

Formal definition

Embezzlement is generally defined as the fraudulent appropriation or conversion of property by a person to whom that property has been entrusted, or into whose hands it has lawfully come. The distinguishing element, relative to simple larceny or theft, is that the perpetrator obtained lawful possession or custody of the property before fraudulently converting it to an unauthorized use. It is frequently characterized as a form of white-collar crime and most often involves the misappropriation of money or financial assets, for example, through fraudulent checks or improper use of a credit card, by employees, officers, fiduciaries, or others in a position of trust. Precise statutory elements, the classes of property covered, and grading (for instance, degree by value) vary by jurisdiction and should be confirmed against the applicable criminal statute; the term is defined here as a criminal-law offense, distinct from any AML compliance determination, and it may serve as a predicate offense for money laundering where a jurisdiction so provides.

Why it matters

Embezzlement matters to financial crime professionals primarily because it can serve as a predicate offense for money laundering where a jurisdiction so provides. When a person lawfully entrusted with funds, an employee, officer, or fiduciary, fraudulently converts them, the resulting proceeds are criminal property that may subsequently be placed, layered, and integrated into the financial system. Understanding embezzlement therefore helps compliance teams recognize how illicit funds may originate before they reach the banking channels that AML programs are designed to monitor.

Who it's relevant to

Compliance Officers and AML Program Managers
Where a jurisdiction recognizes embezzlement as a predicate offense for money laundering, compliance teams need to understand how misappropriated funds may enter and move through the financial system. This informs how internal controls, transaction monitoring, and escalation procedures are designed to detect and manage risk, while recognizing that no single control eliminates financial crime risk.
Financial Intelligence Analysts and Investigators
Analysts examining suspicious activity may encounter conduct consistent with embezzlement, such as misappropriation via fraudulent checks or improper credit card use by individuals in positions of trust. Because the initial access to funds was lawful, identifying the wrongdoing often depends on patterns rather than a single event. Analysts should treat such indicators as prompts for further inquiry, not as proof that a criminal offense has occurred.
Legal and Risk Professionals
Because the statutory elements, classes of property covered, and grading of embezzlement vary by jurisdiction, legal and risk professionals must confirm the applicable criminal statute when assessing whether particular conduct falls within the offense and whether it constitutes a predicate for money laundering in the relevant regime. They also play a key role in separating the criminal-law meaning of embezzlement from any AML compliance determination.
Internal Audit and Fraud Prevention Teams
Given that embezzlement typically involves the misappropriation of an employer's or business's financial assets by trusted insiders, internal audit and fraud prevention functions are often positioned to detect and deter it through controls over access, authorization, and reconciliation. These measures help mitigate and manage the associated risk but do not guarantee its prevention.

Inside Embezzlement

Fiduciary or Positional Trust
Embezzlement typically requires that the offender was lawfully entrusted with the property or funds, often through employment, agency, or another position of trust, rather than obtaining them by force or deception from the outset.
Lawful Initial Possession
A defining feature that generally distinguishes embezzlement from theft or larceny in many jurisdictions is that the offender came into possession of the assets legally before misappropriating them; the wrongdoing lies in the subsequent conversion, not the initial access.
Fraudulent Conversion or Misappropriation
The core act is the diversion of entrusted assets to the offender's own use or to an unauthorized purpose, contrary to the terms under which they were held. Terminology and precise elements vary by jurisdiction and should be confirmed against the applicable criminal statute.
Intent Element
Embezzlement is generally treated as an intentional offense, typically requiring an intent to deprive the rightful owner of the property; specific mental-state requirements differ across legal systems.
Predicate Offense Dimension
In the AML context, embezzlement may function as a predicate offense generating illicit proceeds that are subsequently laundered. Whether and how it qualifies as a predicate depends on the applicable jurisdiction's list of predicate offenses.

Common questions

Answers to the questions practitioners most commonly ask about Embezzlement.

Is embezzlement the same thing as money laundering?
No. Embezzlement and money laundering are distinct concepts, though they are often connected. Embezzlement is a predicate offence describing the fraudulent misappropriation of assets by someone entrusted with them, such as an employee, fiduciary, or agent who lawfully has access to funds but converts them for unauthorised purposes. Money laundering, by contrast, is the process of disguising the illicit origin of proceeds so they appear legitimate. Where embezzled funds are subsequently concealed, moved, or integrated into the financial system, the embezzlement typically serves as the underlying predicate crime that generates the proceeds, while money laundering is the separate conduct of handling those proceeds. In many jurisdictions the two are charged as separate offences, and the classification of embezzlement as a predicate offence for money laundering purposes should be confirmed against the applicable national law.
Does an internal alert or suspicious activity report about possible embezzlement mean an employee is guilty of a crime?
No. An internal alert, an escalation, or a suspicious activity report (SAR) or suspicious transaction report (STR), depending on the jurisdiction, reflects a suspicion or a reasonable-grounds threshold for reporting, not a determination of guilt. These are compliance and reporting mechanisms designed to detect and escalate potentially suspicious conduct to the relevant financial intelligence unit or authorities. Establishing that embezzlement has occurred is a matter for criminal investigation and adjudication under the applicable criminal law, which involves standards of proof that a compliance filing does not meet. A filing, alert, or match should never be treated as proof of wrongdoing.
How might an obliged entity detect indicators potentially associated with embezzlement?
Obliged entities generally rely on a combination of transaction monitoring, internal controls, and staff awareness to identify indicators that may warrant further review. Potential indicators can include transactions inconsistent with an entity's known profile, unexplained movements of funds involving accounts controlled by employees or fiduciaries, circumvention of authorisation controls, or discrepancies between recorded and actual asset positions. These indicators are not exhaustive and do not, on their own, establish that embezzlement has occurred; they are prompts for further inquiry and, where appropriate, escalation. Detection measures serve to help identify and manage risk rather than to guarantee prevention.
What role does customer due diligence play where embezzlement risk is a concern?
Customer due diligence (CDD) supports the identification and understanding of a customer, the nature and purpose of the relationship, and expected activity, which in turn provides a baseline against which anomalies may be assessed. Where risk factors are elevated, enhanced due diligence (EDD) measures may be applied, which can include closer scrutiny of transactions and sources of funds. In the context of potential embezzlement, understanding beneficial ownership and control arrangements can be relevant, since misappropriation may involve individuals with authority over accounts. The specific CDD and EDD obligations, thresholds, and triggers derive from the applicable regime, such as the EU AML framework, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations, and should be confirmed against the relevant instrument.
When should suspected embezzlement be reported, and to whom?
Reporting obligations depend on the jurisdiction and the type of obliged entity. Generally, where an entity forms a suspicion or has reasonable grounds to suspect that funds represent the proceeds of crime, including a predicate offence such as embezzlement, it may be required to file a suspicious activity report or suspicious transaction report with the relevant financial intelligence unit, following any applicable internal escalation process to a nominated officer or money laundering reporting officer. The applicable reporting threshold, timing, format, and recipient body differ across regimes, and tipping-off restrictions may apply. Entities should confirm the precise requirements against the applicable regulation and their internal policies.
How should embezzlement typologies be used within a risk-based approach?
Typologies associated with embezzlement can inform risk assessments, monitoring rules, and staff training by illustrating patterns that have been observed, but they should be treated as illustrative rather than exhaustive or determinative. Within a risk-based approach, they help calibrate controls to the risks a particular entity faces, taking into account its customers, products, delivery channels, and geographies. Controls informed by typologies are measures to detect, deter, and mitigate risk; they do not eliminate financial crime risk, and the presence of a typology-consistent pattern does not by itself confirm that an offence has been committed.

Common misconceptions

Embezzlement and theft are the same offense.
Although both involve the unlawful taking of property, embezzlement generally involves assets the offender was lawfully entrusted with and later misappropriated, whereas theft typically involves unlawful taking from the outset. The precise legal distinction and terminology vary by jurisdiction and should be confirmed against the applicable statute.
Detecting or reporting suspected embezzlement establishes that a crime occurred.
A suspicious activity report, an internal audit finding, or a compliance alert reflects suspicion or an anomaly, not a legal determination of guilt. Whether embezzlement occurred is a matter for criminal adjudication, and compliance filings do not establish wrongdoing.
Embezzlement is only a concern for the victim organization, not for AML programs.
Beyond the direct loss to the entrusting party, embezzlement can generate proceeds that enter the financial system and become the subject of laundering. It may therefore be relevant to AML controls where it constitutes a predicate offense under the applicable regime.

Best practices

Confirm the precise elements and terminology of embezzlement against the applicable criminal statute and jurisdiction rather than assuming a single universal definition, as it is distinguished from theft and fraud differently across legal systems.
Treat internal alerts, audit exceptions, and suspicious activity indicators as signals warranting review, not as conclusive proof of criminal conduct, and document them accordingly.
Consider whether suspected embezzlement may constitute a predicate offense under the relevant regime and assess whether any resulting proceeds could enter the financial system for laundering.
Implement segregation of duties and access controls over entrusted assets as measures to help detect and deter misappropriation by those in positions of trust, recognizing that no single control eliminates the risk.
Where a reporting obligation may arise, route matters through the appropriate internal escalation and reporting channels in line with the applicable jurisdiction's requirements, and confirm any thresholds or filing standards against the governing regulation.
Maintain clear records of the basis for any suspicion and the review undertaken, separating operational compliance conclusions from any characterization of criminal wrongdoing.