Last Updated on 29/08/2026 by 75385885
What the WANdisco Case Teaches Us About the Next Step from GRC to Governance Intelligence
Sales fraud internal controls – Sales fraud can remain hidden even when an organisation has established internal controls, approval procedures and financial reporting controls. The WANdisco case provides a powerful illustration of a broader governance question: can GRC be enriched by connecting control evidence with Governance Reality to identify anomalies that deserve investigation?
A well-designed governance system can contain policies, approval procedures, segregation of duties, revenue–recognition controls, management reporting, internal audit and external audit. Individual transactions can pass through apparently legitimate processes. Risks can even have been identified correctly.
And yet the picture presented to management, the board and investors can still diverge dramatically from economic reality.
The WANdisco case provides a particularly interesting illustration of this problem.
In March 2023, British software company WANdisco announced that it had discovered what it described as “significant, sophisticated and potentially fraudulent irregularities” relating to purchase orders, revenue and bookings represented by one senior sales employee. The consequences were extraordinary. Revenue for 2022, previously expected to be approximately $24 million, could be as low as $9 million. The company withdrew confidence in its earlier revenue guidance, warned of a significant impact on cash and raised material uncertainty concerning its financial position. Trading in its shares on AIM was suspended.
Subsequent reporting on the independent investigation described an even larger problem in sales bookings. According to AAT’s account of the FRP Advisory investigation, more than $115 million of false sales bookings had been identified, while purchase orders associated with the senior employee were found to be illegitimate. The same report states that the other orders examined were legitimate.
It would be tempting to turn this into another familiar story about fraud, failed controls and the need for more compliance.
That would miss the more interesting governance question.
The case invites us to ask something different:
How can an organisation become so dependent on one representation of reality that a major divergence between reported commercial success and underlying economic activity remains insufficiently visible?
That question matters far beyond WANdisco.
It goes to the heart of how Governance, Risk & Compliance — GRC — may evolve as organisations become increasingly data-driven.
1. A historical case, not a reconstruction
An important qualification is necessary at the outset.
This article uses the publicly reported WANdisco case to illustrate a governance concept. It is not a reconstruction of the events, does not attempt to determine what particular individuals knew at particular moments and does not suggest that the analytical approach discussed below would necessarily have discovered or prevented the reported irregularities.
Nor should the article be read as criticism of WANdisco’s management, its auditors or other advisers based on information that became available only afterwards.
Hindsight is a remarkably powerful audit tool.
The more useful exercise is prospective: what can organisations learn from a case like this when designing the next generation of governance monitoring?
That distinction is important because the objective is not to build a machine that retrospectively labels transactions as fraudulent. It is to improve an organisation’s ability to recognise when different parts of its own operational reality cease to tell a coherent story.
sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls
2. One employee, an enterprise-wide consequence
There is something striking about the scale asymmetry in this case.
At one end was reportedly one senior sales employee. At the other end were revenue, bookings, cash expectations, financial reporting, investor information, the company’s share price and ultimately questions about financial viability.
Between those two points sat an entire organisation.
WANdisco was not a tiny business operating from a spreadsheet. It was a listed technology company with operations in Sheffield and California and more than 180 employees. Its software supported large-scale migration of data to the cloud. According to the AAT account, its customers included organisations such as Google and Amazon.
That makes the governance problem especially instructive.
A large commercial transaction does not normally exist only inside the sales department.
It has consequences.
A customer needs to exist. Commercial negotiations take place. A contract or purchase order is produced. Products or services must eventually be delivered. Implementation resources may need to be allocated. Revenue recognition criteria must be satisfied. An invoice may be raised. A receivable emerges. Cash should ultimately arrive. Forecasts change. Sales commissions may become payable. Customer support activity may follow.
The transaction creates what might be called an economic footprint across the enterprise.
This is where the distinction between control evidence and governance reality begins to matter.
Read more in the Guardian on: Software firm WANdisco suspends shares amid ‘fraudulent irregularities’.
3. Traditional GRC was asking the right questions
The easiest conclusion from a case involving false sales would be:
The controls failed.
But that statement is too crude to be analytically useful.
Traditional GRC has brought enormous discipline to organisations. Risks are identified and assessed. Controls are assigned to risks. Control owners are established. Policies define required behaviour. Segregation of duties reduces inappropriate combinations of authority. Compliance requirements are mapped. Exceptions are recorded. Controls are tested. Internal Audit provides independent assurance.
These mechanisms are indispensable.
Indeed, one detail in the WANdisco case makes simplistic criticism particularly inappropriate.
According to AAT, BDO’s 2021 independent auditor’s report had identified specific risks of fraud and error concerning inappropriate revenue recognition because of the nature of the group’s customer contracts. The auditor also referred to the risk of manipulation of revenue through manual journal entries.
In other words:
The risk itself was not necessarily invisible.
This changes the governance discussion.
The question is no longer merely whether the organisation had identified revenue recognition as a risk.
The more interesting question is whether governance technology can go further and continuously compare the different manifestations of economic reality that should accompany reported commercial activity.
That is not a replacement for GRC.
It is an extension of what GRC has already made possible.
4. The difference between a valid control and a valid reality
Consider a simplified sales process.
A company may require a purchase order before recognising a transaction. The purchase order is present. The document contains the expected fields. The appropriate employee has processed it. Required approvals appear to have occurred.
From a control perspective, those observations are relevant evidence.
But imagine that the organisation simultaneously contains other information:
The customer has almost no previous commercial history.
No corresponding implementation project has started.
No delivery resources have been reserved.
Billing is substantially delayed.
Receivables associated with a particular salesperson are ageing differently from the rest of the portfolio.
Cash conversion is materially below that of comparable customers.
Customer-support activity is absent.
Reported bookings attributable to one salesperson have increased dramatically while the operational organisation supporting those bookings has hardly changed.
None of these observations individually proves anything.
There may be perfectly legitimate explanations for every one of them.
Large contracts can have unusual payment schedules. Software companies can sign deals months before implementation. Enterprise customers may have complicated procurement structures. Revenue and cash rarely move in perfect synchronisation.
That is precisely why governance intelligence should not behave like a fraud detector.
Its role is more subtle.
It asks whether the combined evidence remains sufficiently coherent to support the reality being reported.
5. Follow the transaction beyond Finance
Traditional financial analysis often ends up following transactions towards the general ledger.
That makes sense. The financial statements ultimately emerge from the accounting system.
But economic activity moves in the opposite direction.
It starts in the business.
Consider a simplified value chain:
Customer → Opportunity → Contract → Purchase Order → Booking → Delivery → Revenue → Invoice → Receivable → Cash
Not every business will follow this exact sequence, and software businesses can have particularly complex contractual and revenue–recognition structures.
Nevertheless, genuine commercial activity usually leaves multiple traces.
This gives us a powerful governance principle:
The larger the reported economic event, the more organisational evidence we should normally expect it to generate.
A $10 million booking should not merely produce a $10 million number in a sales report.
Somewhere in the organisation there should normally be a customer, commercial correspondence, contractual obligations, delivery expectations, operational consequences, financial consequences or future cash expectations consistent with that booking.
Governance therefore becomes partly a question of relational integrity.
Do the different parts of the organisation recognise the same underlying economic event?
6. From individual transactions to populations
This leads to another important distinction.
Many controls assess individual transactions.
Was this order authorised?
Was this journal approved?
Was this customer created correctly?
Was the appropriate contract documentation present?
Was revenue recognised in accordance with the applicable accounting policy?
These are necessary questions.
But organisational behaviour exists at another level as well: the population.
Suppose Sales Executive A produces 400 transactions.
Each transaction, viewed individually, looks plausible.
Now compare the complete population with those of other sales executives.
Perhaps Executive A generates:
- an unusually high proportion of very large contracts;
- significantly shorter sales cycles;
- unusually high quarter-end bookings;
- substantially lower conversion from bookings into invoices;
- longer delays between contracting and implementation;
- much lower subsequent cash conversion.
The individual transactions may still appear ordinary.
The collective behaviour is not.
This is an important governance insight:
A population of individually plausible transactions can collectively describe an implausible organisational reality.
Traditional control testing and population analysis therefore answer different questions.
One asks whether the transaction complies with the expected control.
The other asks whether the behaviour emerging from thousands of transactions remains consistent with the organisation’s expected economic model.
Both matter.
Also reda this: How one individual’s dishonesty can undermine an entire business on aatcomment.org.uk (The Association of Accounting Technicians).
7. The Three Governance Realities
This distinction can be formalised through three different views of governance.
Governance Design
This is the organisation as intended.
Policies, procedures, delegated authorities, risk frameworks, internal controls, system configurations, segregation of duties and accounting policies define how business should be conducted.
Governance Design answers:
How are we supposed to operate?
Governance Execution
This is evidence that the governance design is actually being performed.
Were approvals completed? Were reconciliations executed? Were exceptions investigated? Were access rights reviewed? Were controls tested?
Governance Execution asks:
Did we perform the governance activities we designed?
Collective Governance Behaviour
This is the reality that emerges when the organisation actually operates.
Customers behave. Employees make decisions. Contracts accumulate. Orders flow through systems. Products are delivered. Services are performed. Receivables age. Cash arrives. Exceptions cluster. Overrides occur.
Collective Governance Behaviour asks:
What does the organisation’s actual behaviour tell us?
The three should broadly reinforce each other.
But they are not identical.
An organisation can have excellent Governance Design and substantial evidence of Governance Execution while still developing patterns of Collective Governance Behaviour that deserve attention.
That is the space in which the concept of Governance Reality becomes valuable.
8. What might Governance Reality have asked at WANdisco?
We need to be careful here.
We do not have the underlying WANdisco datasets and therefore cannot claim that any particular analytical signal existed before the irregularities were discovered.
But we can use the case to construct a theoretical governance analysis.
Imagine that a governance system had access — subject to appropriate permissions and data governance — to CRM data, customer master data, contracts, purchase orders, sales bookings, implementation activity, invoices, receivables, cash receipts and perhaps sales commissions.
Instead of searching for “fraud”, the system compares relationships.
It might ask:
Do bookings attributed to each salesperson convert into operational activity at broadly explainable rates?
Do customers associated with exceptionally large bookings subsequently display the economic characteristics expected of customers of that size?
Does revenue growth correspond with growth elsewhere in the enterprise?
Are concentrations emerging around particular employees, customers, periods or transaction types?
Are there transactions whose documentary evidence exists but whose wider operational footprint is unexpectedly weak?
These are not accusations.
They are management questions generated from organisational evidence.
And that difference is fundamental.
9. An anomaly is the beginning of an investigation, not its conclusion
Suppose an analytical system finds that one salesperson accounts for an exceptionally large proportion of new bookings.
There is nothing inherently wrong with that.
The salesperson may simply be outstanding.
Now suppose those bookings have unusually little subsequent implementation activity.
Still not evidence of wrongdoing.
Perhaps the salesperson specialises in long-term contracts.
Suppose cash conversion is also substantially lower.
Again, there may be an explanation.
Then suppose the relevant customer relationships are relatively new, sales cycles are unusually short and order values are materially larger than comparable transactions.
The individual observations remain inconclusive.
But together they form a pattern.
A well-designed governance-intelligence system should not display a flashing red screen saying:
FRAUD DETECTED.
It should say something much more useful:
The commercial activity associated with this population differs materially from comparable activity and is not yet fully supported by the expected operational and financial evidence. Management review is recommended.
Then it should show why.
That final requirement is crucial.
If an algorithm cannot show the evidence behind its conclusion, governance has merely replaced human opacity with technological opacity.
10. Evidence to investigate, not evidence to convict
This brings us to perhaps the most important lesson from the WANdisco case for the future development of GRC technology.
An anomaly is not proof of misconduct.
It is not even proof that a control has failed.
It is evidence that something deserves explanation.
That distinction should be embedded in the architecture of governance technology.
A Governance Control Navigator-type analysis should therefore produce a traceable chain:
Observed signal → underlying transactions → connected business objects → expected relationship → observed divergence → management question
For example:
Sales Executive X represents an unusually high proportion of new bookings.
That statement alone is weak.
But the system could subsequently show that the signal arises from 37 identified bookings, associated with 12 customers, of which a defined proportion lacks the operational patterns normally observed within a specified period after comparable bookings.
Management can inspect the underlying transactions.
Perhaps the explanation is completely legitimate.
If so, the governance process has worked.
The objective was never to catch someone.
The objective was to make an unexplained divergence visible, traceable and investigable.
And that is where Governance Reality begins to add something genuinely different to the established GRC architecture.



