The Association of Certified Fraud Examiners (ACFE) structures the corporate fraud landscape into a uniform classification hierarchy known as the Occupational Fraud and Abuse Classification System (The Fraud Tree). This framework organizes internal corporate crimes into three main classification lines supported by specific operational sub-categories. [1]
                  ┌──────────────────────────────────────────────┐
                  │            THE ACFE FRAUD TREE               │
                  └──────────────────────┬───────────────────────┘
                                         ▼
         ┌───────────────────────────────┼───────────────────────────────┐
         ▼                               ▼                               ▼
[Asset Misappropriation]        [Corruption Schemes]            [Financial Statement Fraud]
• Cash Larceny & Skimming       • Bribery & Bid Rigging         • Overstating Current Revenues
• Invoice & Billing Schemes     • Economic Extortion            • Understating Liability Logs
• Expense Reimbursement Fraud   • Conflicted Asset Transfers    • Deceptive Disclosure Notes

Every risk register entry should map directly to one of these three Fraud Tree categories:
  1. Asset Misappropriation: The most frequent typology, encompassing schemes where an employee steals or misuses the organization’s resources. This category is split into cash schemes (e.g., billing schemes, ghost payroll, inventory theft) and non-cash schemes (e.g., proprietary data exfiltration or unauthorized equipment usage).
  2. Corruption: Involves schemes where an employee uses their corporate influence to violate their duty to the organization for personal gain. This includes bribery, bid rigging, kickback schemes, and illegal gratuities that compromise corporate procurement lines. [1]
  3. Financial Statement Fraud: The least frequent but most severe typology, involving the deliberate misstatement or omission of financial facts to mask the true economic performance of the enterprise. [1]