Fraud investigation and litigation support
When fraud risks grow alongside operational complexity, protecting your organization becomes even more challenging. Investigate concerns and strengthen controls with Wipfli.
How we help you
Wipfli’s fraud investigation and litigation support helps you prevent, identify and address fraud with proactive support for meeting increasing threats and operational complexity.
Identify and mitigate critical fraud risks.
Minimize loss and maximize recovery.
Stay ahead of evolving risks across your operations.
Prevent, detect and investigate fraud and misconduct
Wipfli has developed a multidisciplinary team with strong experience in financial forensics, digital forensics, litigation support, economic damages and IT controls.
Explore our fraud investigation and litigation support services
Wipfli can help your organization identify, quantify and mitigate fraud risks, costs and effects. We provide support in performing assessments, investigations proactive examinations and designing antifraud programs and controls.
We can also help you address:
- Anti-bribery
- Corruption
- Contract compliance
- Corporate intelligence
- E-discovery
- Financial crimes
- Fraud and misconduct
Wipfli’s litigation and dispute advisory team can help you minimize your risk of loss and maximize the opportunity for recovery. Depending on your needs, we offer a comprehensive range of litigation support consulting, from pre-litigation strategy up to and including expert witness testimony at trial.
We can also support your organization with:
- Calculation of lost profits and other economic damages.
- Financial matters consultation with attorneys.
- Lifestyle analyses (financial statement analysis, daily living expenses reconstruction, cash-flow reporting, income tax return analysis, marital lifestyle and post-separation analysis).
- Information gathering, evaluation and formal reporting.
- Preparation for and participation in depositions.
Insights and Resources
- Learn More
EVENT | January 19, 2027
January 2027 Uniform Guidance regulation training
Join us for a practical and engaging virtual training of the Office of Management and Budget’s (OMB) Uniform Guidance (2 CFR Part 200) — the cornerstone of federal grant compliance. This training is designed to help nonprofit and government professionals understand federal grant regulations and how to apply them effectively and avoid common pitfalls in managing federal awards. Led by experienced trainers with years of auditing and consulting expertise, this session blends regulatory review with real-world examples and actionable insights. Whether you’re new to federal
Learn MoreARTICLE
Cyber risk management: How to reduce cyber risk across your business
As cybersecurity threats grow ever more potent, your business needs to adapt. This starts with adopting a more cohesive cyber risk management strategy to protect your operations, finances and reputation. Embracing a cyber risk strategy elevates cybersecurity beyond being just an IT concern into a core pillar of your overall enterprise risk management efforts — which helps make your whole organization safer and more resilient. Keep reading to learn more about why this approach matters, plus how to get started. What is cyber risk management? Cyber risk management is a strategy that addresses cybersecurity and cyber resilience as enterprise-level risks rather than siloed problems for your IT department. This proactive approach, which also contrasts with compliance-based models of cybersecurity that focus on meeting compliance requirements, aims to not just stop cyberattacks but also help you recover more quickly if an attack does break through your defenses. Executing a cyber risk management strategy involves identifying cyber-related threats or risks, assessing your current defenses, controls, governance and backup capabilities, strengthening your protections to meet your current risks and then making continuous improvements as needed. The end result is a business that is better able to navigate today’s threat environment and avoid significant losses. If your business has an overall enterprise risk management strategy to mitigate your risk in all areas (not just cybersecurity), then your cyber risk management efforts will fit neatly into that framework. Why cyber risk management matters for business leaders Cybersecurity incidents — like a data breach, business email compromise or ransomware attack — increasingly impact not just large corporations, but businesses of all sizes. That impact shows up directly on your balance sheet. A successful ransomware attack can cost you an upfront ransom payment that may stretch as high as seven figures, as well as ongoing financial, operational and reputational damages ranging from lost productivity or customers to regulatory fines. This isn’t a hypothetical. In one prominent incident, hackers compromised domain-level credentials for Stryker’s Microsoft ecosystem and used that access to remotely wipe data from up to 200,000 company laptops and phones, severely disrupting its worldwide operations. Consider what costs might you incur if you were suddenly locked out of your core systems or lost access to your most sensitive internal or customer data (or worse, found it for sale on the dark web)? In this environment, you can’t afford to write off cyberthreats as minor inconveniences. A cyberattack is a genuine risk to your business, no different than a new competitor, changing customer needs or a sudden hit to your supply chain. Cyber risk management is a way to recognize that — and act accordingly. Core components of an effective cyber risk management program An effective cyber risk management program views cyber risk as an enterprise-level challenge for your entire business to address and mitigate. Key aspects of this effort include establishing effective governance, identifying risks and continuously adapting to meet them. Governance and executive oversight Strong governance and active executive oversight help move cybersecurity from a siloed problem to an enterprise risk management issue. Governance helps mitigate your cyber risks by putting controls and policies around which technology you use and how you use it, while an executive leader like a chief information security officer (CISO) or vCISO can bring a strategic, big picture perspective to cyber risk that your frontline IT team doesn’t have. Risk identification and prioritization To mitigate your risks, you have to know them, so a cyber risk management strategy involves identifying the actual threats your business faces. But you can’t be strong everywhere, all the time, so it’s equally important to prioritize those threats and devote your resources to stopping the most urgent or dangerous. Continuous improvement and monitoring Cybersecurity threats are constantly evolving, so your risk strategy needs to, too. This involves active, ongoing cybersecurity and cyber resilience efforts, as well as a continuous assessment of what’s working and what needs to get better in light of your current threat environment. Build cyber resilience before an incident happens Cyber resilience is an essential aspect of cyber risk management that is focused on helping your business maintain operations during a cyberattack or recover more quickly after the attack ends. Cyber resilience is essentially a complementary activity to cybersecurity, which aims to stop attacks from succeeding in the first place. The overall goal of cyber resilience is to protect business continuity so that your team, customers, finances and outputs are less affected by a cyberattack. This is important because in today’s threat environment, it is unlikely you will be able to stop all cyberattacks at all times, so emphasizing cyber resilience means you will be better able to move forward if and when a breach occurs. It’s important to focus on cyber resilience before a breach or incident occurs. If you’re prepared ahead of time, then you’ll be ready to respond faster and with greater confidence. You’ll also have already taken steps, like backing up your data, that will make it easier to get back to business as usual. Assess your organization’s cyber readiness Understanding your cyber risks and your readiness to address them is key to managing your overall risk levels. But this can’t just be a one-time exercise. Cybersecurity-related risks are constantly changing. AI has made it easier than ever for even individuals without technical knowledge to launch attacks, and both the scope and vector of threats continue to evolve. That’s why you should think of assessing your cyber risks and readiness as an ongoing process. Ideally, this process should have executive leadership in the form of a CISO or vCISO (potentially a CIO in smaller organizations), and a third-party advisor can also provide an invaluable outside perspective that can help you identify gaps your internal team may be too close to notice. Establish strong cybersecurity governance Strong cybersecurity programs are built on a foundation of governance and effective leadership. Governance is crucial to understanding your risks and implementing the appropriate strategies to address them. Additionally, a CISO or vCISO can provide the leadership you need to help oversee the program, communicate with stakeholders and embed cybersecurity into culture and operations. As part of strong governance, your cybersecurity program should include: Annual cybersecurity program assessments to help ensure your program aligns with organizational objectives, regulatory requirements and best practices. Annual tabletop exercises that help you rehearse and strengthen staff’s incident response. Annual board security awareness sessions where your CISO educates leadership on cybersecurity risks, strategies and responsibilities. Quarterly employee training so that staff are aware of cyberthreats and equipped to defend against them. Implement a cyber risk framework A cyber risk framework is an organized, structured strategy for understanding and managing your cyber risks. A framework essentially lays out a series of actions or steps for your business to take to become better equipped to protect against and recover from cyber-related threats. You don’t need to develop your own cyber risk framework. Organizations like NIST and ISO have created detailed frameworks that you can use, sparing your team from attempting to reinvent the wheel. However, you may need help from a third-party advisor to successfully choose and implement a framework. Depending on your specific industry and needs, a particular framework may make more sense than other options or may even be necessary from a regulatory standpoint. Cyber risk management best practices Here are two best practices to help your business more successfully manage your cyber risk levels: Maintain active cyber defenses Cybersecurity operations (SecOps) refer to the tools, processes and personnel needed to monitor, detect, investigate and respond to security threats in real time. It’s a critical component of any cybersecurity program, helping protect your organization’s assets against evolving threats. Your SecOps can include: Endpoint detection and response to monitor activity on endpoints — such as laptops, desktops, servers and mobile devices — to detect threats and respond to them quickly. 24/7 security monitoring to detect threats in real time. Log retention to support forensic investigation if an incident does occur. DNS filtering to help prevent access to potentially malicious websites or sites you want to restrict. Threat intelligence to help you apply information about emerging cyberthreats to strengthen your defenses. Dark web monitoring to help identify any instances where your organization’s sensitive information may have been compromised. Regular vulnerability scanning to help your team proactively detect and address potential entry points before attackers can exploit them. Quarterly firewall configuration reviews to maintain strong defenses and align firewall rules with current security policies and business needs. With the right SecOps practices in place, you can minimize risk, reduce incident response time and maintain business continuity . Keep testing to find gaps Cybersecurity testing is your opportunity to evaluate your current level of effectiveness, with assessments and simulated attacks that can help identify any vulnerabilities, misconfigurations or weaknesses. Your cybersecurity program should include annual testing activities such as: Penetration testing, including internal tests to assess how far an attacker could go after gaining initial access and external testing to identify vulnerabilities in perimeter defenses. Comprehensive vulnerability assessments that identify, classify and prioritize security weaknesses across your organization’s entire IT environment. Cloud security reviews that provide a structured evaluation of your cloud environment to help ensure data, applications and services are properly secure. Social engineering tests, including phishing and pretext-calling attacks, to assess how staff recognize and respond to cybercriminals’ manipulation tactics. Ransomware attack simulations to test your organization’s ability to identify and respond to ransomware incidents. How cyber risk management supports enterprise risk management Effective cyber risk management serves as a supporting pillar of your overall enterprise risk management strategy. Think of cyber as one leg of a table, working in conjunction with other legs like operational risk, AI risk, regulatory risk and technology risk. As more businesses embrace enterprise risk management as a way to adapt to today’s uncertain business environment, operate more effectively and even identify growth opportunities, becoming better able to tackle cyberthreats is a critical part of that effort. To learn more about how managing risk can make your whole business stronger, work with a risk advisor to assess your vulnerabilities and understand your opportunities. Read more How to become a more cyber-resilient organization Cybersecurity is now a major financial risk Enterprise risk management: A strategy for turning risk visibility into business wins
Learn MoreARTICLE
CDD Rule: What financial institutions need to know
The Financial Crimes Enforcement Network’s (FinCEN) recent actions regarding the Corporate Transparency Act (CTA) and Beneficial Ownership Information (BOI) reporting have created significant confusion within the financial services industry. Many institutions have asked whether FinCEN’s decision to eliminate BOI reporting requirements for U.S. companies means that they are no longer required to collect and verify beneficial ownership information at account opening. The short answer is no. While FinCEN has substantially narrowed the scope of the CTA’s BOI reporting regime, the agency has not eliminated financial institutions’ Customer Due Diligence (CDD) obligations under the Bank Secrecy Act (BSA). Financial institutions must continue to identify and verify beneficial owners of legal-entity customers in accordance with the CDD Rule unless FinCEN formally amends those requirements. The CTA reporting framework and the CDD Rule are related, but they are separate regulatory requirements. What changed under the CTA? On March 26, 2025, FinCEN issued an interim final rule that dramatically narrowed BOI reporting requirements under the CTA. The rule revised the definition of a “reporting company” so that only certain foreign entities registered to do business in the United States remain subject to BOI reporting obligations. Domestic entities and U.S. persons were exempted from reporting BOI to FinCEN. FinCEN’s Final Rule on BOI reporting under the Corporate Transparency Act (CTA) was issued on August 11, 2026, and became effective upon publication in the Federal Register on August 14, 2026. Under the final rule, domestic reporting companies remain exempt from BOI reporting. U.S. beneficial owners are exempt from providing BOI. FinCEN also announced that information relating to U.S. persons will be removed from the BOI database. Only certain foreign reporting companies formed under foreign law that are registered to do business in a U.S. state or tribal jurisdiction remain subject to CTA reporting obligations. These changes represent a significant scaling back of the CTA’s original reporting framework. However, they apply only to the requirement that companies report ownership information directly to FinCEN. They do not eliminate customer due diligence obligations imposed on financial institutions. The critical distinction for FIs: CTA reporting vs. CDD requirements One of the most common misconceptions is that the CTA and the CDD Rule are the same thing. They are not. The CTA created a reporting obligation requiring certain entities to submit BOI directly to FinCEN. By contrast, the CDD Rule requires covered financial institutions to identify and verify beneficial owners of legal-entity customers when accounts are opened and at certain triggering events. The information is collected and maintained by the financial institution as part of its BSA/AML program. The purpose is to help institutions understand who owns and controls their customers and to support risk-based monitoring and suspicious activity reporting. Although Congress envisioned that the BOI database could eventually reduce compliance burdens for financial institutions, FinCEN has not rescinded or replaced the CDD Rule. Accordingly, institutions remain subject to the existing beneficial ownership requirements contained in the BSA framework. How the February 2026 exceptive relief differs FinCEN’s February 13, 2026, Exceptive Relief Order, FIN-2026-R001, addressed the frequency with which financial institutions must identify and verify the beneficial owners of legal-entity customers. The order permits an institution to obtain and verify beneficial ownership information when the legal-entity customer first opens an account, rather than each time the same customer opens an additional account. Updated identification and verification remain necessary when the institution knows facts that reasonably call the reliability of previously obtained information into question or when required under its risk-based ongoing CDD procedures. This relief differs from the August 2026 CTA Final Rule. The exceptive relief modifies how financial institutions apply the CDD Rule, while the CTA Final Rule limits which companies and individuals must report BOI directly to FinCEN. Neither action eliminates a financial institution’s underlying obligation to identify and verify beneficial owners under the CDD Rule. As a result, examiners will continue to expect institutions to: Identify legal-entity customers Collect beneficial ownership information Verify the identity of beneficial owners Maintain appropriate records Conduct risk-based ongoing customer due diligence These obligations remain foundational components of an institution’s BSA/AML compliance program. How financial institutions should proceed The recent narrowing of the Corporate Transparency Act’s BOI reporting requirements is a significant regulatory development, but it should not be interpreted as eliminating beneficial ownership requirements for financial institutions. It does not eliminate the separate obligations imposed on institutions under the CDD Rule. Until FinCEN formally amends the CDD Rule, financial institutions should continue collecting and verifying beneficial ownership information at account opening for legal-entity customers and maintain risk-based procedures consistent with existing BSA/AML expectations. Institutions that incorrectly interpret CTA reporting relief as eliminating beneficial ownership requirements under the CDD Rule risk creating significant compliance gaps that could lead to examination findings and/or regulatory criticism. Read more How financial institutions can verify their CECL compliance Avoiding adjustable-rate mortgage loan compliance challenges What financial institutions should prioritize in a CRM
Perspective changes everything.
Receive timely industry developments, regulatory changes and other news impacting your success.
Reach out to our team
Connect with our team for experienced support in identifying, investigating and mitigating your fraud risk.


LET'S CONNECT
See how Wipfli can help you implement risk management that supports compliance, productivity and long-term success.






