Misappropriation

Misappropriation is unauthorized use of entrusted assets or, in U.S. insider-trading law, confidential information used in breach of a duty. Learn the distinctions and controls.

Misappropriation is the unauthorized taking, use, transfer, or diversion of money, securities, information, or other property entrusted to a person or organization. In finance, the term commonly appears in two distinct contexts: misappropriation of assets, such as diverting client or company funds, and the U.S. securities-law misappropriation theory of insider trading, which concerns deceptive use of confidential information for securities trading in breach of a duty owed to the information’s source.

Those meanings should not be merged. Asset misappropriation concerns control or use of property. The insider-trading theory concerns confidential information and a particular legal basis for securities-fraud liability. Whether conduct is theft, embezzlement, fraud, breach of fiduciary duty, insider trading, or another offense depends on the governing law and proven facts.

Key Takeaways

  • Misappropriation generally involves unauthorized use of property or information that the person obtained through access, custody, authority, trust, or another relationship.
  • In auditing, asset misappropriation can involve stolen receipts, unauthorized payments, fictitious vendors, payroll schemes, securities transfers, inventory theft, or concealed personal use of company assets.
  • Under the U.S. misappropriation theory of insider trading, liability is not established merely because someone possesses material nonpublic information. The source of the information, duty, deception, trading or tipping conduct, and other legal elements matter.
  • Misappropriation, theft, embezzlement, fraud, insider trading, and market manipulation overlap in some fact patterns but are not interchangeable legal labels.
  • Segregation of duties, independent custody, dual authorization, direct statements, reconciliations, access controls, and escalation channels can reduce opportunity and improve detection.
  • A control exception, unusual transfer, whistleblower report, or suspicious trade is evidence to investigate, not proof that a named person committed misconduct.
  • Legal definitions, procedures, remedies, and penalties vary by jurisdiction. Allegations should be described as allegations unless supported by a final finding or admission.

Two Finance Meanings

ContextWhat may be misappropriated?Typical fact patternMain evidence
Asset misappropriationCash, securities, inventory, data, customer property, or another assetA person with access redirects an asset for unauthorized personal or third-party useBank and custodian records, approvals, invoices, access logs, reconciliations, communications, and beneficial-owner data
Misappropriation theory of insider tradingConfidential information used for securities trading or tippingA person uses information obtained through a relationship of trust or confidence in breach of a duty to its sourceInformation source, duty, confidentiality terms, materiality, public status, communications, trade records, timing, and benefit

The same case can involve both. For example, an adviser could divert client cash and falsify account statements, creating asset misappropriation, books-and-records, custody, fraud, and fiduciary issues. A lawyer who uses a client’s confidential acquisition information to trade may implicate the securities-law misappropriation theory without taking the client’s cash.

Misappropriation of Assets

The Public Company Accounting Oversight Board’s AS 2401 describes misstatements arising from misappropriation of assets as theft of an entity’s assets when the theft causes the financial statements not to be fairly presented in all material respects under GAAP. Examples include embezzling receipts, stealing assets, or causing payment for goods or services not received. False or misleading records may be used to conceal the activity.

The auditing definition is scoped to financial-statement misstatement. It does not mean smaller thefts are lawful or irrelevant. An immaterial amount for financial-statement audit purposes can still violate law, policy, contract, or fiduciary duties and can reveal a serious control weakness.

Common Asset Schemes

SchemeHow value is divertedPossible concealment
Cash-receipt skimmingCustomer payment is taken before or after recordingMissing receipt, write-off, altered customer balance, or delayed deposit
Fictitious vendorFalse supplier is created and paidFabricated invoice, approval override, or matching documents
Expense reimbursementPersonal or false expense is charged to the entityAltered receipt, duplicate claim, or misleading business purpose
Payroll diversionFalse worker, hours, account, or compensation is processedGhost employee, changed bank details, or unauthorized bonus
Client-asset transferCash or securities leave a client account without proper authorityFalse instruction, forged approval, related-party account, or false statement
Securities or inventory theftTradable assets or goods are removed or pledgedFalse count, valuation adjustment, write-off, or altered custody record
Unauthorized personal useCompany card, vehicle, property, data, or service is used privatelyMisclassification as business expense or omitted disclosure

Misappropriation can occur without a sophisticated accounting entry. It may also be concealed through management override, collusion, false confirmations, side agreements, or control access that allows the same person to initiate and hide a transaction.

Worked Example: Fictitious Vendor Payment

Assume an employee can create vendors, enter invoices, approve payments below 25,000, and reconcile the bank account. The employee creates a company controlled by a relative and submits three invoices for services never received:

InvoiceAmount
Invoice 1$18,000
Invoice 2$16,500
Invoice 3$13,500
Total diverted$48,000

If the payments are recorded as legitimate consulting expense, cash is understated correctly because it left the bank, but expense is misclassified and overstated while the theft or related loss is concealed. Vendor records, approvals, expense detail, related-party information, and the bank reconciliation may also be unreliable.

A useful investigation would not begin and end with the journal entry. It would preserve:

  • vendor onboarding data and beneficial ownership;
  • invoice files, service evidence, purchase orders, and approvals;
  • user-access and change logs;
  • bank instructions and destination-account details;
  • email, messaging, and conflicts disclosures;
  • reconciliations and reviewer sign-offs; and
  • similar payments before and after the identified period.

The control failure is concentration of incompatible duties. One person could create the payee, authorize the payment, and conceal it in the reconciliation. Separating those functions would not guarantee prevention, but it would make unauthorized activity harder to execute and hide.

Client Funds and Securities

Client-asset misappropriation is especially serious because the asset belongs to another party and may be held under contractual, fiduciary, custody, segregation, or regulatory obligations. Risk can arise when a professional or affiliate can possess assets, withdraw them, change payment instructions, deduct fees, act as trustee or general partner, or control the records clients rely on.

The SEC’s investment-adviser custody framework uses safeguards intended to protect client funds and securities from loss, misuse, or misappropriation. Which requirements apply depends on the current rule, adviser status, asset, custody arrangement, account structure, and exceptions. A custody-rule violation is not itself proof that assets were stolen, but custody weaknesses can increase opportunity and reduce independent verification.

Practical safeguards can include:

  • maintaining assets with an appropriate independent custodian where required;
  • titling and segregating accounts correctly;
  • sending statements directly from the custodian to the client;
  • reconciling adviser reports with custodian records;
  • independently verifying fee calculations and withdrawals;
  • restricting changes to bank and wire instructions;
  • requiring callback or out-of-band confirmation for transfers;
  • reviewing related parties and conflicts;
  • limiting privileged system access; and
  • investigating discrepancies rather than carrying unexplained reconciling items.

Registration, a reputable custodian, an audit, or a clean prior examination cannot eliminate fraud risk. Controls must operate, exceptions must be investigated, and clients should verify that communications and account details are authentic.

The Misappropriation Theory of Insider Trading

In U.S. securities law, the misappropriation theory addresses certain trading by people who may owe no duty to the shareholders of the company whose securities are traded. The theory focuses on deception of the source that entrusted the person with confidential information.

The U.S. Supreme Court’s decision in United States v. O’Hagan upheld liability where a lawyer used confidential information obtained through his law firm’s client relationship to trade securities connected to a planned acquisition. The SEC explains the theory as misappropriating confidential information for securities trading purposes in breach of a duty owed to the source.

This is narrower than saying, “Trading on any nonpublic information is misappropriation.” A legal analysis can require questions such as:

  • Was the information material and nonpublic?
  • Who was the source?
  • What fiduciary, contractual, or other relationship of trust and confidence existed?
  • What duty was owed to the source?
  • Was the information obtained, disclosed, or used deceptively?
  • Did the person trade, cause trading, or tip another person?
  • What did the person know, and when?
  • Which security, transaction, statute, rule, and jurisdiction are involved?
  • Does a tender-offer rule, trading plan, disclosure, consent, or other provision change the analysis?

Insider-trading law is fact-specific and has developed through statutes, rules, and cases. Insider Trading should not be inferred solely from a profitable trade, employment title, friendship, family connection, or access to information.

Worked Example: Confidential Acquisition Information

Suppose a consultant is retained by Company A for a confidential potential acquisition of Company B. The agreement and circumstances require the consultant to keep the information confidential. Before any public announcement, the consultant buys Company B call options and tells a friend that an announcement is likely.

The fact pattern raises potential misappropriation-theory and tipping questions because the information came from a source to whom the consultant may owe a duty. A proper review would examine the engagement terms, access records, communications, option trades, account ownership, funding, timing, public disclosures, and the friend’s knowledge.

The facts do not become a legal conclusion merely because the trades were timely and profitable. Materiality, nonpublic status, duty, deception, use, knowledge, personal benefit where relevant, jurisdiction, and procedural posture require legal analysis. Public reporting should distinguish an internal alert, regulatory investigation, filed charge, settlement, admission, verdict, and final judgment.

TermCore ideaWhy it is not identical
MisappropriationUnauthorized diversion or use of entrusted property or informationBroad descriptive term with context-specific legal meaning
EmbezzlementFraudulent conversion of property entrusted to or lawfully possessed by the accused, under the applicable lawOften a criminal offense with jurisdiction-specific elements
Theft or larcenyWrongful taking or control of another’s propertyPossession, taking, intent, and offense labels differ by law
FraudDeception or misrepresentation causing or seeking an unlawful benefit or harmCan occur without taking entrusted assets; legal elements vary
Insider tradingUnlawful securities trading or tipping under applicable inside-information rulesMisappropriation theory is one U.S. basis for liability, not the entire field
Market ManipulationConduct intended or operating to create a false or misleading market or price under applicable lawFocuses on market activity rather than entrusted assets or source duties
Breach of fiduciary dutyViolation of duties arising from a fiduciary relationshipMay support a civil claim without satisfying every element of fraud, theft, or insider trading

The ordinary-language overlap should not replace the charging document, statute, court order, regulator finding, contract, or internal investigation record.

How Misappropriation Affects Financial Reporting

Asset misappropriation can distort more than cash. Depending on the scheme, financial statements may contain:

  • fictitious expense, asset, vendor, employee, loan, or receivable balances;
  • missing inventory, securities, or cash;
  • understated liabilities or related-party disclosures;
  • false revenue credits, refunds, write-offs, or allowances;
  • inaccurate custody, client-asset, or restricted-cash disclosures;
  • incorrect tax deductions or reporting; and
  • contingent losses, legal costs, recoveries, or insurance claims requiring evaluation.

Auditors consider fraud that could result in material financial-statement misstatement, but management is responsible for designing and maintaining controls. An external audit provides reasonable, not absolute, assurance and is not designed to discover every immaterial theft or legal violation.

When a loss is suspected, accounting questions can include whether an asset still exists, when the loss occurred, whether recovery is probable, how insurance should be treated, whether prior statements require correction, and what disclosure is required. Those questions depend on evidence and the reporting framework.

Prevention and Detection Controls

    flowchart TD
	    A["Define ownership, custody, authority, and permitted use"] --> B["Separate initiation, approval, custody, recording, and reconciliation"]
	    B --> C["Authenticate counterparties, instructions, and access"]
	    C --> D["Reconcile independent records and review exceptions"]
	    D --> E{"Unexplained variance, transfer, access, or trade?"}
	    E -->|"No"| F["Document review and continue monitoring"]
	    E -->|"Yes"| G["Preserve evidence and restrict further exposure"]
	    G --> H["Investigate, escalate, remediate, and report when required"]
	    H --> I["Test recovery, accounting, disclosure, and control correction"]
	    I --> D

No single control is sufficient. Stronger programs combine preventive, detective, and responsive controls:

ControlRisk addressedLimitation
Segregation of dutiesOne person causing and concealing a transactionCollusion or management override can defeat separation
Dual approvalUnauthorized payment or transferApprovers can rubber-stamp or share credentials
Independent custody and statementsAdviser or manager controlling both assets and reportingFake websites, impersonation, or ignored discrepancies remain possible
Bank and ledger reconciliationMissing, duplicate, or diverted cashReconciler needs independence and source access
Vendor and account validationFictitious or changed payeeRelated-party ownership may be concealed
Access controls and logsUnauthorized system use or record changesExcess access or unreviewed logs weaken detection
Restricted lists and information barriersMisuse of confidential deal or issuer informationPoor data mapping and off-channel communication can bypass controls
Whistleblower and complaint channelsHidden conduct known to employees or clientsFear, poor triage, or retaliation can suppress reporting
Mandatory leave and role rotationLong-running concealment dependent on one personNot effective if replacement performs no independent review

Controls should be proportionate to asset value, liquidity, transferability, system access, transaction speed, customer vulnerability, and prior incidents.

Warning Signs and Evidence

Potential indicators include unexplained transfers, altered payee details, missing original documents, stale reconciliations, duplicate payments, lifestyle anomalies, related-party vendors, dormant-account activity, repeated overrides, unusual access times, statement differences, customer complaints, and trades near confidential events.

Each indicator can have an innocent explanation. A sound review:

  1. preserves records and limits unnecessary disclosure;
  2. identifies who owned the asset or information and who had access;
  3. reconstructs authorization, transaction, custody, recording, and settlement;
  4. obtains independent bank, broker, custodian, vendor, or system evidence;
  5. distinguishes error, policy breach, control failure, and intentional conduct;
  6. involves legal, compliance, audit, security, human-resources, or law-enforcement specialists as appropriate; and
  7. documents findings, uncertainty, recovery, reporting, remediation, and follow-up.

An accusation can seriously harm a person or firm. Investigators and publishers should use careful language and protect evidence, confidentiality, due process, and applicable reporting obligations.

Common Mistakes

  • Treating misappropriation as only an AML customer-identification concept.
  • Calling every unexplained accounting difference theft or fraud.
  • Saying any trade based on material nonpublic information automatically satisfies the U.S. misappropriation theory.
  • Confusing the source duty in misappropriation theory with a duty owed only to the traded company’s shareholders.
  • Using theft, embezzlement, fraud, conversion, and misappropriation as universal legal synonyms.
  • Assuming an audit is designed to detect every theft regardless of size or financial-statement effect.
  • Letting one person initiate, approve, hold, record, and reconcile assets or payments.
  • Relying only on internally produced statements when independent custody evidence is available.
  • Publicly describing allegations as proven findings.
  • Assuming recovered money eliminates the accounting, control, legal, disclosure, or customer-harm consequences.

Risks and Limitations

  • Legal-definition risk: Offense names and elements vary by jurisdiction and claim.
  • Evidence risk: False records, collusion, deleted messages, nominees, and offshore transfers can obscure ownership and intent.
  • Control-override risk: Senior personnel or privileged users may bypass otherwise sound procedures.
  • False-positive risk: Unusual transactions and timely trades can have legitimate explanations.
  • Recovery risk: Tracing an asset does not ensure it can be frozen, returned, or collected.
  • Custody risk: Concentrating assets, authority, recordkeeping, and reporting increases the ability to conceal diversion.
  • Cyber risk: Account takeover and impersonation can resemble insider theft while involving external actors.
  • Reporting risk: Delayed escalation can worsen loss, compromise evidence, and create additional regulatory exposure.
  • Reputation and fairness risk: Unsupported accusations can harm innocent people and interfere with investigations.

Authoritative Sources

This page provides general financial education. It does not determine whether conduct is criminal, fraudulent, actionable, material, reportable, or attributable to a specific person. Current law, regulator rules, professional standards, contracts, and verified evidence control each case.

  • Fraud: Deceptive conduct that may accompany asset or information misappropriation but has its own legal elements.
  • Insider Trading: Securities-law field that includes classical and misappropriation theories and other rules.
  • Internal Control: Processes designed to support reliable reporting, authorized transactions, safeguarded assets, and compliance.
  • Fiduciary Duty: Duties arising from a fiduciary relationship that can be relevant to entrusted assets or confidential information.
  • Market Manipulation: Conduct affecting market price or activity through prohibited deceptive or artificial practices under applicable law.

FAQs

Is misappropriation the same as embezzlement?

Not universally. Embezzlement is often a specific criminal offense involving fraudulent conversion of entrusted property. Misappropriation is a broader descriptive term whose legal meaning and required elements depend on the jurisdiction and context.

What is asset misappropriation in an audit?

PCAOB AS 2401 describes it as theft of an entity’s assets when the effect causes a material financial-statement misstatement. Examples include embezzled receipts, stolen assets, or payments for goods or services not received.

What is the misappropriation theory of insider trading?

It is a U.S. securities-law theory concerning deceptive use of confidential information for securities trading in breach of a duty owed to the information’s source. Possession of nonpublic information alone is not a complete statement of the test.

Does a suspicious payment prove misappropriation?

No. It is an indicator requiring preservation and investigation of authorization, ownership, purpose, custody, records, counterparties, and intent. Error, policy breach, control weakness, and deliberate diversion are different conclusions.

Which controls can reduce asset misappropriation risk?

Useful controls include segregation of duties, dual authorization, independent custody and statements, reconciliations, payee verification, restricted access, reviewed logs, conflict checks, and protected escalation channels. No control eliminates fraud risk.
Browse Regulation