Services Process Why QoEPro Resource Library FAQ Contact Order a Report →

How to Handle Embezzlement Discovered During Due Diligence

A theft loss looks like the cleanest addback a seller will ever hand you. It rarely is. The three-condition test for when embezzlement actually belongs in adjusted EBITDA, and what to do when it doesn't.

The veterinary clinic made no sense.

The waiting room was packed. Demand outran capacity. Several employees had been there for years. And the P&L showed a business losing money.

A practice that busy doesn't lose money by accident, so I pulled cost of goods sold (COGS) and a handful of operating expense lines, flagged four accounts that sat well outside what a practice that size should run, and sent one question back through the business development rep: What happened here?

About ten days later, he called. He had driven out to the owner's house, and the two of them ended up on a bench in the back yard because the owner couldn't stay standing.

His daughter, who ran the clinic as its office manager, had embezzled roughly $500,000. She hadn't just taken money and left a trail. She'd used false bookkeeping entries to disguise the withdrawals as cost of goods sold, so the theft was sitting inside the same account that was supposed to explain why medical supplies and lab costs looked normal. The owner never caught it. Neither did the CPA who prepared the clinic's returns every year. It only surfaced because the owner went back and pulled the transactions behind the four accounts I'd flagged.

Take the theft out and the clinic made good money. Leave it in and it lost money. Nobody was lying about any of it, and there was no reason to think his daughter would keep stealing under new ownership. By every normal rule of thumb, that's an addback.

Except the entire adjusted EBITDA of that business was riding on it, and the person accused of taking the money was also the one who kept the books and hid it. I didn't yet know which entries were real COGS, which were fabricated, how long the scheme had run, or whether $500,000 was the whole story.

The real question wasn't whether money had been stolen. It was whether anyone could reliably say what the clinic would have earned without her.

The Core Idea

An addback is a forward-looking claim about what a business earns after you own it. Employee theft can satisfy that claim, but only once the loss is bounded, the cause is genuinely removed, and the number is documented outside the seller's own account. Fail any one of the three, and "non-recurring" is an assumption, not an underwriting conclusion.

A real loss is not automatically an addback

An addback removes an expense that won't continue under new ownership. By that definition, employee theft looks about as clean as an addback gets.

It's tied to one person and a non-recurring event. Unlike owner compensation, there's no argument over a market salary. Unlike personal expenses, there's no debate over which costs were partly business-related. Remove the employee, stop the theft, and the seller's case looks straightforward.

From the seller's side, it can also feel like simple fairness. Pricing the business off earnings that were reduced by a robbery can feel like treating the robbery as a normal operating cost. I understand that reaction. It's a fair one.

But an addback isn't a judgment about blame. It's a forward-looking claim about what the business earns after you own it, and that claim gets a lot harder to support once the person accused of stealing is also the person who controlled the books.

In this deal, the theft was buried inside false entries coded to COGS. The accounting records weren't just under-reporting the loss. They were part of how she pulled it off.

That distinction changes everything about how you handle it. If an employee wires herself $100,000 in one identifiable transaction, isolating the adjustment is straightforward. If an office manager manipulates vendor entries and disguises withdrawals as ordinary operating costs for years, you can't just reverse one number and call the result normalized EBITDA. You don't know how much of that account is even real.

Before I'd accept an adjustment like that, I need three things: The full size and duration of the loss, proof that whatever let it happen has actually been fixed, and reconstructed earnings that don't rely on the same compromised books that hid the theft in the first place. Until those exist, "non-recurring" is an assumption. It isn't an underwriting conclusion.

The three-condition test

I test a theft-related addback three ways. Bounded, remediated, documented. Fail any one and the adjustment doesn't belong in the number a buyer or a lender underwrites.

1. Is the loss bounded?

Meaning: Do you know the full amount and time span of the theft, or just the piece somebody happened to find?

Discovery in these situations is almost always partial. Someone digs into one unusual account, finds an alarming number, and treats it as the answer. It isn't. It's the first confirmed data point.

Nobody starts by taking $500,000. The first transaction is small, nothing happens, and the number grows because nothing keeps happening. By the time a scheme is large enough to bend a P&L, it's usually been running for years and usually reaches past the account where it was first spotted. The ACFE's 2024 Report to the Nations puts the typical occupational fraud scheme at about a year before detection, and found weak or absent internal controls a factor in more than half of all cases. Neither number is surprising once you've watched a discovery happen in real time.

Here, the owner found roughly half a million dollars by looking exactly where I'd pointed ... four accounts, the periods I'd flagged. But because she'd recorded the transactions as COGS, every entry touching those accounts needed a second look. Legitimate medical supply purchases were sitting right next to entries that may have been fabricated. Nobody had traced the full population back to bank statements, cleared checks, vendor records, or actual goods received. Nobody had checked earlier years or any other account she could reach. We knew the floor. We had no idea what the ceiling was.

An unbounded loss can't support a precise addback, because you don't yet know what amount you're reversing. It's just as hard to size an escrow or a specific indemnity around a number nobody has finished counting.

2. Has the cause been remediated?

Removing the employee is necessary. It isn't sufficient.

She could set up vendors, record the transaction, and reconcile the account, all without anyone else looking. Fire her tomorrow and you've stopped that one person. You haven't touched the reason nobody else caught it.

So ask the harder question. Who controls vendor setup now? Who approves payments? Who records the entry, and who reconciles the bank account, and is it the same person doing all four? Does anyone independent ever look at the bank statement itself, or does the general ledger get taken on faith? If one person can still create a vendor, initiate a payment, record it, and reconcile the account, the risk hasn't gone anywhere. It's just been handed to whoever fills the job next.

You aren't buying last year's theft. You're buying the system that let it stay hidden. Until that system changes, the cost isn't safely non-recurring. It's a control failure waiting for its next form.

3. Is the loss documented?

The seller's account of what happened isn't enough, even when the seller is candid and the story is true.

A police report, an insurance claim, a civil filing, a restitution agreement, a forensic accountant's report ... any of these help establish that the theft happened and support the amount. But when the books themselves were the weapon, documentation has to do more than prove money went missing. It has to separate the real operating costs from the fabricated ones and support what the business would have earned without the scheme running underneath it.

That means evidence outside the compromised ledger. Bank statements pulled directly from the bank. Cleared checks. Vendor invoices. Purchase histories. Inventory records. Tax filings.

None of that existed yet in this deal. No forensic reconstruction, no claim filed, no clean period under a new office manager. She was still on payroll, and the same accounting process was still in place.

Bounded? No. Remediated? No. Documented? No. The loss may have been real. The adjusted EBITDA was not.

Two ways to establish normalized earnings

Once the books themselves are compromised, there are only two credible paths to a defensible addback. Reconstruct the past, or establish a clean future.

Reconstruct the past through forensic work

A forensic accountant traces the suspect transactions from the general ledger to the bank and back out to independent support. For a scheme buried in COGS, that usually means pulling bank statements and cleared check images straight from the bank, matching invoices to purchase orders and goods actually received, hunting for fictitious vendors and altered payees, reviewing who could change the vendor master, and checking whether anyone else was involved.

This is a different scope than a standard QoE. A QoE can spot that something's wrong, challenge the seller's proposed adjustments, and show that the reported earnings don't add up. That's what happened here, and it was enough to change the deal. A forensic engagement goes further: It reconstructs the transactions and produces a defensible answer for what was taken, how, and over what period. When the theft is embedded in operating expenses and represents a meaningful share of adjusted EBITDA, that reconstruction may be the only way to support a historical addback at all.

The seller should generally pay for this work. He's the one asking a buyer and a lender to rely on earnings his own records can no longer prove.

Establish a clean operating period

Sometimes the better answer is to stop trying to reconstruct every historical month and instead show what the business earns under new controls. Replace the office manager, separate bookkeeping from anyone who can move cash, rebuild the approval chain, and run it long enough to produce numbers you can trust.

For this clinic, I wanted a full year of clean books before I'd lean on the proposed adjustment. Twelve months captures the seasonality, gives you enough transactions to test recurring COGS, and lets you compare revenue, margin, payroll, and cash flow under the new system. Three clean months can show the bleeding stopped. It usually can't carry a valuation or a lender's debt service test on its own.

This route delays the sale. Sometimes delay is the price of making a business financeable again.

What the diligence scope must cover

The theft doesn't sit neatly inside one addback. It can touch the income statement, the balance sheet, the tax returns, the working capital peg, and the legal protections in the purchase agreement, all at once.

The income statement. If false entries were coded to COGS, historical gross margin isn't reliable, full stop. You need to know whether reported medical supplies, pharmaceuticals, and lab costs reflect actual purchases, comparing them against practice volume, inventory usage, and vendor statements. If real and fabricated transactions are mixed together, you can't normalize gross margin with one broad adjustment. Revenue can be entirely real while the margin underneath it stays a question mark.

The balance sheet and working capital. A scheme routed through COGS can distort inventory, payables, accrued expenses, and cash. Fictitious purchases without real inventory arriving means inventory and payables won't reconcile. Altered checks after entry mean the ledger shows one vendor while the bank shows another. Either one contaminates the historical averages your working capital peg is built on. Base the peg only on periods and accounts you actually trust. If none exist, you're looking at a delayed peg analysis or a post-closing true-up built on verified balances instead.

The tax returns. If the stolen funds were disguised as deductible expenses, prior returns may carry overstated or misclassified deductions, which can mean amended filings. Get a tax attorney's read before you assume the deal structure protects you. In a stock purchase, historical liabilities generally travel with the entity. An asset purchase gives more separation, but it isn't an automatic cure for every payroll, sales tax, or successor liability question, and that varies by state.

The control environment. Document the whole cash disbursement process, not just the one employee accused. At minimum, vendor creation, payment approval, bookkeeping, and bank reconciliation shouldn't sit with one person. Someone who can't initiate or record payments should be the one reviewing bank statements. Vendor and payment instruction changes should need a second signature. COGS should get checked against purchasing activity and volume, not accepted because it landed in the right account. The specific controls vary by business. The principle doesn't: Nobody should be able to start, hide, and clear the same transaction alone.

The people. When the person is family, or has been there for years, the fallout goes past the accounting. Other employees may have known something, suspected something, or simply gotten used to weak processes. In a practice where a handful of producers carry most of the revenue, disruption among key staff is a real underwriting risk, not a soft one. Find out who knew what, who's still loyal to whom, and whether the seller is actually willing to enforce the changes the business now needs.

Documentation, recovery, and deal protection

Once a loss is known, don't assume the standard reps and warranties will cover it. Known issues generally need specific treatment in the price and the agreement, not a general clause.

Build the independent record. A forensic accountant's report. A police report. An employee dishonesty or crime insurance claim. A civil complaint. A signed restitution agreement. Bank and vendor records supporting the reconstructed number. When the perpetrator is family, an owner is often reluctant to file any of it, and that reluctance is understandable. It still has a cost. A loss nobody independently investigated is a loss a buyer, a lender, an insurer, or a court has a harder time relying on. Tell the seller what documentation the deal needs early, while the evidence is still fresh. Waiting until the last week of diligence closes off options that existed in week one.

Decide who owns the recovery. Insurance proceeds, restitution payments, and civil judgments tied to a pre-closing loss need to be spelled out in the purchase agreement: Who bears the historical loss, who pays for the investigation, who gets any recovery after closing, whether the buyer owes cooperation. A recovery receivable generally doesn't belong in working capital. It isn't part of the operating cycle and it won't replenish itself.

Protect against what's still unknown. A known theft with an unbounded tail doesn't get solved by a generic indemnity or a seller's word that the number is complete. Depending on the facts, you may need some combination of a lower price, a delayed closing, a specific indemnity for pre-closing theft and related tax exposure, an escrow sized to the remaining uncertainty, a seller note or earnout that shifts some of the risk, or a closing condition requiring the employee's removal and the new controls to already be in place. One thing rarely helps here: Representations and warranties insurance. Carriers exclude known issues as a matter of course, so a disclosed theft is exactly the kind of risk that policy won't touch. The exact structure belongs to your attorney. The financial principle is simpler. Don't pay today for earnings nobody has proven yet.

What each party should do

If you're the seller, get the employee away from cash and the books immediately, preserve everything, and bring in counsel, a forensic accountant, and whoever handles your insurance. Rebuild the controls, then either commission the reconstruction or run clean long enough to produce earnings a buyer can trust on their own. Do not hand a buyer the discovered number and call it a finished addback just because the theft itself is real.

If you're the buyer, treat this as an earnings problem and a control problem at once. Widen the diligence scope well past the account where the anomaly showed up. Don't lean on the same general ledger that hid the theft as your evidence for the adjustment. Ask for an independent reconstruction, a clean operating period, or both, and if the seller can't produce either, underwrite off the earnings you can actually verify. Not the earnings everyone hopes are sitting underneath the theft.

If you're the lender, the question is whether the adjusted cash flow is repeatable and provable for debt service. Calling a large theft addback "non-recurring" doesn't make it safer when it's built on compromised books. Until the loss is bounded and the normalized earnings are demonstrated, that adjustment deserves little to no credit in the lending case.

Frequently asked questions

Is embezzlement an EBITDA addback?

Not automatically. A theft loss only becomes a defensible addback once it passes three tests: The full size and duration of the loss are bounded, the person and the control gap that allowed it are both removed, and the loss is documented outside the seller's own account. Fail any one of the three and the adjustment doesn't belong in adjusted EBITDA.

What happens if fraud is discovered during due diligence?

Diligence widens rather than stops. The buyer needs to determine how far back the scheme runs, whether it touches other accounts, and whether the same control weakness is still in place. Depending on what's found, the deal can proceed with a price adjustment, a delayed closing, a specific indemnity, an escrow, or it can end entirely.

Does a QoE report detect employee theft?

A Quality of Earnings review can identify anomalies, such as expense accounts running well outside the expected range, that lead to a theft being discovered. It isn't a forensic audit. Once theft is suspected, a forensic accountant is typically needed to trace the transactions, quantify the loss, and produce documentation that can support an insurance claim, indemnity, or legal action.

Should you walk away from a deal after finding embezzlement?

Not necessarily. Many buyers proceed once the loss is bounded, the responsible employee is gone, the controls are rebuilt, and the business has run for a defined clean period under the new system. The decision to walk usually comes down to timing: Whether that remediation can happen before the buyer needs to close, not whether the theft occurred.

How do you document a theft loss for a purchase agreement?

Useful documentation includes a police report, an employee dishonesty or crime insurance claim, a civil filing, a signed restitution agreement, or a forensic accountant's report, supported by bank statements and vendor records obtained independently of the compromised books. The seller's verbal account of what happened isn't sufficient on its own.

The decision

The clinic may well have been a good business underneath the theft. The packed waiting room, the loyal staff, the demand nobody could keep up with ... all of it pointed that way.

But buyers don't pay for what a business might earn once the books get fixed. They pay for earnings they can verify and reasonably expect to continue.

Removing the office manager would have been step one, not the whole answer. Because she'd concealed the theft through false entries coded to COGS, the historical financials couldn't support a simple addback. The seller needed either a forensic reconstruction that traced every dollar back to the bank, or a full year of clean operations under someone new and controls that actually worked.

Until one of those existed, the proposed EBITDA wasn't necessarily wrong. It was unproven.

The Bottom Line

Unproven earnings shouldn't set a purchase price, or a lender's number either.

This article discusses tax and legal issues in general terms. It is not tax or legal advice. Buyers and sellers facing an actual discovery like this one should engage qualified counsel and a tax advisor before making any decision based on it.

Sources
  1. Association of Certified Fraud Examiners, Occupational Fraud 2024: A Report to the Nations (typical detection window, prevalence of internal control weaknesses, and median loss data).
About QoEPro

QoEPro performs independent Quality of Earnings reviews for buyers and sellers in the lower middle market, from independent sponsors and search fund entrepreneurs to owners preparing for a sale. Our job isn't only to verify the numbers. It's to help buyers understand whether the business they're acquiring performs the way it's been presented. View report options →