Case IQ and Compliance Week surveyed 328 compliance officers about retaliation. See the results. Read the findings.

Sometimes the most instructive fraud cases aren't the ones involving an extraordinarily complicated scheme. They're the ones that demonstrate how seemingly ordinary business processes can be exploited over an extended period of time.

A recent case involving a former Bridgestone Americas Assistant Treasurer provides exactly that kind of lesson.

On August 11, 2026, the U.S. Attorney's Office for the Middle District of Tennessee announced that Sajju Khatiwada, a former Assistant Treasurer at Bridgestone Americas, pleaded guilty to two counts of wire fraud in connection with a scheme that caused the company to pay nearly $15 million in fraudulent invoices.

According to the DOJ, Khatiwada created a fictitious vendor called Paymt-Tech, LLC in July 2020, registering the company under the name of an acquaintance and opening bank accounts in the vendor's name. From August 2020 through April 2024, he allegedly sent fraudulent invoices to other Bridgestone employees on a monthly basis for purported service charges.

The DOJ says Paymt-Tech performed no services for Bridgestone. Yet over the course of the scheme, Bridgestone paid $14,923,978.57 into accounts controlled by Khatiwada.

There are obviously facts about Bridgestone's internal processes that are not included in the DOJ's announcement, and we should not speculate about controls the company did or did not have in place.

But the facts the government has made public offer several broader lessons for compliance, internal audit, and finance teams.

Lesson 1: A Control at One Point in the Process Isn't the Same as Continuous Oversight

Companies have spent years strengthening front-end controls around vendors and payments.

Those controls are essential. Organizations should know who they are doing business with, understand the purpose of the relationship, conduct appropriate due diligence, and establish approval processes.

But fraud does not necessarily stop because a process exists.

A bad actor may provide false information, exploit an exception, circumvent an approval process, or otherwise find a way around an individual control.

That makes the activity occurring after an approval equally important.

In the Bridgestone case, the DOJ alleges that fraudulent invoices were submitted monthly over a period approaching four years. That raises a useful question for every organization—not about Bridgestone specifically, but about our own programs:

If an inappropriate transaction made it through our controls today, what would detect it tomorrow?

Historically, the answer might have been an audit, an investigation, or a whistleblower report.

Those mechanisms remain important. But they are inherently different from continuously analyzing transactional data for indicators of risk.

Lesson 2: Don't Just Look at Transactions. Connect the Data Around Them.

One of the limitations of traditional monitoring is that transactions are often reviewed in isolation.

An invoice may not appear particularly remarkable on its own. Neither may an individual vendor payment.

Risk becomes much more visible when multiple pieces of information are connected.

For example, organizations can analyze vendor master data alongside purchase requisitions, purchase orders, invoices, and payments. They can also incorporate relevant employee and third-party information.

That allows compliance and audit teams to ask more sophisticated questions:

  • Is a payment unusual compared with previous payments to the same vendor?
  • Was an invoice paid unusually quickly?
  • Was a payment made without an expected purchase order?
  • Does vendor information unexpectedly match employee information?
  • Is a vendor receiving recurring payments that differ from the behavior of comparable vendors?
  • Does one transaction trigger several different risk indicators simultaneously?

The important concept is context.

A single indicator can generate significant noise. But when several risk indicators converge on the same transaction, vendor or employee, the picture can become much more meaningful.

That's why I have long advocated aggregated risk scoring rather than simply creating independent lists of red flags.

Lesson 3: Monitoring 100% of Transactions Changes the Detection Model

Traditional auditing has an unavoidable limitation: sampling.

If an organization processes hundreds of thousands or millions of transactions, humans cannot manually review all of them. Auditors therefore select samples and examine those transactions more closely.

There is nothing inherently wrong with sampling, and audits continue to play an important role.

But a sample can only detect what is inside the sample.

Modern data analytics gives organizations another option.

Rather than selecting a small number of transactions and hoping the relevant activity is included, technology can apply risk analytics across the full population of transactions and prioritize higher-risk activity for human review.

That distinction is important.

The objective isn't to have compliance professionals manually investigate every transaction. It's almost the opposite.

Technology should do the repetitive work of examining large data populations so that skilled compliance, audit, and investigations professionals can spend their limited time on the transactions that warrant additional scrutiny.

At Case IQ, for example, our Compliance Monitoring software risk scores every transaction using more than 85 pre-built statistical, behavioral, and policy-based analytics, along with machine learning. Higher-risk transactions can then be escalated for human review.

Technology does not make the final compliance decision. It helps people determine where to look.

Lesson 4: Look for Combinations of Risk, Not Just Big Numbers

One temptation in financial monitoring is to focus primarily on value.

Show me our largest payments. Show me our top 20 vendors. Show me our biggest expense reports.

Those can be useful views, but fraud doesn't have to involve the largest transaction in a dataset.

Imagine an otherwise ordinary vendor payment that also happens to:

  • differ substantially from the vendor's historical payment pattern;
  • lack an expected purchase order;
  • be paid much faster than normal;
  • contain unusual invoice characteristics; and
  • have vendor information that matches information associated with an employee.

Any one of those factors might have a legitimate explanation.

Together, however, they could justify a closer look.

This is where multidimensional analytics can be much more useful than simply ranking transactions by dollar value.

The goal should be to find transactions with the greatest risk, not necessarily the transactions of the greatest amount.

Lesson 5: Monitoring Should Become More Intelligent Over Time

A mature compliance monitoring program shouldn't remain static.

Every review creates new information.

When a transaction is investigated and cleared, the organization learns something about what constitutes normal behavior. When an issue is substantiated, the organization learns something about its actual risk patterns.

Those results should be fed back into the monitoring program.

Rules and thresholds can be refined. New analytics can be introduced. Machine-learning models can learn from reviewer feedback. Emerging schemes can be incorporated into the monitoring methodology.

The result is a feedback loop:

Detect. Review. Learn. Refine.

That is a fundamentally different model from conducting the same periodic review year after year.

Lesson 6: The Best Monitoring Program Still Requires Human Judgment

There is a tendency in discussions about analytics and AI to imply that technology can eliminate fraud.

It can't.

No compliance monitoring system will guarantee that every instance of wrongdoing is detected, just as no approval workflow, audit, or hotline can guarantee that result.

The objective is to improve the organization's probability of detecting problematic behavior earlier and give compliance professionals better information with which to make decisions.

That's also why false-positive reduction matters so much.

If a monitoring system produces thousands of alerts without meaningful prioritization, the compliance team has simply traded one haystack for another.

The better approach combines strong rules-based analytics, statistical techniques, and machine learning with human expertise. Technology narrows the field. Experienced professionals interpret the context and decide what to do next.

From Periodic Detection to Continuous Assurance

The Bridgestone Americas case is ultimately a useful reminder of something simple: misconduct can occur inside familiar, everyday processes.

An invoice arrives. Someone approves it. A payment is made.

Repeat that process enough times, and seemingly ordinary transactions can accumulate into extraordinary losses.

That is why the future of compliance monitoring isn't simply about adding more controls. It's about creating visibility across the lifecycle of a transaction and continuously testing what is actually happening in the business.

Compliance teams already have access to enormous amounts of data through ERP, travel and expense, procurement, HR, and other enterprise systems.

The opportunity is to turn that data into an early-warning system.

At Case IQ, that is the philosophy behind our Compliance Monitoring solution: continuously analyze transactional activity, combine multiple indicators into meaningful risk scores, use AI and machine learning to improve prioritization, and give human reviewers the context they need to investigate the transactions that matter.

Because the real question after a case like this shouldn't simply be, "How did this happen?"

It should be: "What can we change so that the next unusual pattern becomes visible sooner?"

Learn More About Case IQ

See how Case IQ can help your organization reduce fraud and compliance risk

Book a call with one of our experts to learn how our suite of compliance, case management, and hotline solutions can help your organization stay ahead of risk.

Ready to Transform Your Investigation Process?

Join 80,000+ professionals who trust Case IQ to streamline their case management and ensure compliance.