the credit union connection logo white

Unpacking the Dark Side of Credit Union Crime with Deron Rossi

CUC Podcast_Deron Rossi

Let’s face it: when you picture a financial fraudster, Hollywood loves to feed us images of shadowy criminal masterminds hacking mainframe systems in hoodies. But the reality? It’s often much closer to home—and far more human.

In a recent episode of The Credit Union Connection podcast host Sarah Snell Cooke caught up with 30-year credit union volunteer and seasoned internal fraud investigator Deron Rossi to pull back the curtain on why trusted insiders go rogue, how technology is changing the game, and what institutions of all sizes can do before it’s too late.

Fraud isn’t going away, and hoping it passes you by is a losing strategy. As Rossi puts it: Fighting fraud is a team sport.

Watch or listen to the full episode for the full breakdown on red flags, culture fixes, and how to bulletproof your credit union.

NOTE: This transcript may contain minor imperfections courtesy of our AI overlords-in-training. We’re not complaining. We’re definitely not complaining.

Sarah Snell Cooke: Welcome everyone. I am Sarah Snell Cooke, your host here at the Credit Union Connection. Almost forgot my own name. I’m joined today by Deron Rossi. Welcome.

Deron Rossi: Hey there. Good morning.

Sarah Snell Cooke: Ah, good morning. And Deron…I knew him originally a board member at Coastal Credit Union, in North Carolina. And by day, though, he is an internal fraud investigator, which I thought was super interesting. So I don’t know if you want to say a little bit more about yourself and your background.

Deron Rossi: Sure. Two things. One, I’m still with Coastal, 30 years this year as a volunteer, so pretty proud of that, and did five years prior to that on the supervisory committee at Visions Federal Credit Union, prior to moving down south here for IBM. And I’ve been doing fraud, controls, that type of work for a lot of my adult career, but specifically my last 10 plus years at IBM, I did investigations of fraud and conduct issues in North America, and actually was loaned out to work overseas. And now in my semi-retirement role, I’m still doing them. I’m actually in the midst of one really large investigation right now at a large institution here. So it’s all fun, and it never goes away, unfortunately.

Sarah Snell Cooke: It’s never going away, yes. Human nature. How did you get into fraud investigations, internal fraud investigations?

Deron Rossi: So I was, as I’ve alluded to, I was in corporate accounting at IBM, and we were actually moving some roles over to Slovakia, and I looked and said, at some point, maybe my role will move out too. So let me get out in front of it. And I started talking to a peer. I was actually helping a peer who was doing an investigation. She said, “You should join our group. You have so much experience.” So long story short, they recruited me, and I did it, and I did it for over 10 years. So what was interesting is you’d turn on your system in the morning, and you didn’t know what was gonna be out there. Very different than corporate accounting, where we did this on first work day and this on second work day. This was very unstructured, and that’s what made it really interesting. I gravitated to it, and like I say, I’m even doing it now, even though I’ve retired, so to speak.

Sarah Snell Cooke: And so how did you get into credit unions, though?

Deron Rossi: So the credit union originally, this is going back, history lesson, back when I was at Visions, I had done an audit against a certain area. They were using… there was a freeze on capital spending. So these guys said, “You know what? We’re still gonna buy stuff. We’ll just charge it to expense,” which is not the way to do it accounting-wise, and I had to do an audit, wrote them up. They got clubbed over the head. And then one day, the chair of Visions came to my office, and I said, “Pat…” His name was Pat Volpe, and I said, “Pat, I never thought you’d walk this far over to see me, at the plant. Come on in, my friend. What can I do for you?” And he said, “Have you ever heard of the supervisory committee?” And I said, “No, I’m not sure what that is.” And he goes, “Do you belong to Visions?” I go, “Oh, yeah, definitely. Great credit union.” And he explained it all, and I said, “Sure, if you’ll take somebody this young on the committee, I think I can lend some expertise.” And that’s how I got involved, and of course, the rest is history, right? I’ve really loved the industry, love what we do, and been a volunteer now for 35 years. Wow. That’s why my hair’s so white. What little that I got up there, huh?

Sarah Snell Cooke: Dang, you still have it, though. Why do people, and particularly trusted people like within a financial institution…

Deron Rossi: …

Sarah Snell Cooke: …commit internal fraud? Are they all bad criminals? Do they go in with the intention? What happens that makes somebody commit something like this?

Deron Rossi: That’s a great question. I go back to something called the fraud triangle. Okay. And it’s an old concept. It is not a new concept, but it’s still relevant even today. So you have three sides to a triangle. You have the pressure side of it, that kind of starts off. It’s like the thing that lights the dynamite off, so to speak, and that’s what is the pressure? It could be they’re getting a divorce, they have financial trouble, they’re living beyond their means, they have a drug addiction, they have an alcohol addiction, whatever it is, but there’s some pressure that comes into their life that says, “This isn’t enough. I need to get more.” And then the next side of the triangle is the rationalization. So today there’s babies being born in your hospital near you and some here in our hospital, and none of them are probably fraudsters, I’d say right now, right? But as life goes on, they have to justify their means. So they say, “I deserve it.” I used to hear that all the time. “I’m number one.” I met with so many number one salespeople at IBM. I said, “Wow, we must have a tie with 15 of you, are all the number one salespeople. This can’t be.” So they get something in their life that has that pressure. Then it’s, “Okay, how do I justify this? Everyone’s doing it. I deserve more.” That’s usually what it is. And then the last piece, and this is the important piece at the bottom of that circle, is how do you control that? See, if you can put the controls in place to not allow that to happen, then that’s where you can put a lid on it, ’cause everyone might have financial trouble, doesn’t mean they’re a fraudster. Everyone might start justifying, “Gosh, I’m working harder than that guy over there, and why aren’t I getting something?” But it’s that bottom piece, if you can stop that from happening, and that’s where the internal controls come in, that’s where education comes in, that’s where having the tone at the top is very important. I think we’re gonna talk about something later on that kind of ties in with that. All very important. You got that: the pressure, the rationalization, and the opportunity. We gotta take away that opportunity. And nowadays, that triangle’s still the same thing. You still have those three factors working. You would hope things are more sophisticated, that bottom piece that I keep talking about, the opportunity piece, is locked down, but we have things like AI, we have things like hacking. We have all kinds of new stuff, and these are very industrious folks a lot of times. They will find a way. They are very hardworking at their craft, and it’s hard to stay in front of them. In fact, just one quick sideline. When I do presentations, whether it be at a conference for credit unions or non-credit unions, I start with a question: “How many of you think fraud’s gonna increase, decrease, stay the same, or you don’t know?” And right now, informally, I have them raise their hand, so I don’t have exact numbers, but it’s probably running 80 to 85% think it’s gonna increase. And it’s usually controls people in the crowd, so it’s like, “Okay, I’m glad you’re here, and that’s why we’re gonna all learn together.” A long answer maybe to the question, but I really wanted to lay out that triangle, because that really still is relevant, and it just depends on that person and what they’re going through. I don’t think they come to work their first day with that in mind, but there’s things that happen in their life that create that pressure.

Sarah Snell Cooke: Yeah. No, it’s completely logical, too. Aligns with human nature. And like you said, not that everybody who has financial pressure becomes drug addicted or whatever is going to be a fraudster, but it certainly could be a sign for it, for sure. And especially, like right now, all the online betting games, that’s… I, we, by the way, we do welcome side quests here.

Deron Rossi: Okay, good.

Sarah Snell Cooke: That’s good. So anyway, yeah. That’s one of the things that I think, you know, could really bring additional pressure is the growth of all these online football betting games and stuff like that. But anyway, so obviously the triangle survived the test of time, but how has internal fraud evolved during your career?

Deron Rossi: I think the prize is usually that money. Sometimes it’s recognition as well, but it’s usually something financial. So that’s probably stayed the same. But what’s evolved around it are the methodologies. Certainly doing things more electronic. You’re not as old as I am, but you might have been around when they had paper receipts and expense accounts with a staple and a signature and all that. So those things of creating fake documents, believe it or not, still happens. People create fake documents to submit, whether it be electronic or not electronic. So I think adding in the electronic, adding in people being able to sign on and do different things, maybe they have more authorization than they should. So that’s back to that opportunity, right? If we’ve given somebody authorization to do every job in the accounts payable process from setting up the vendor to approving it, to cutting the checks, to reconciling the account, guess what? We just gave away a lot of that opportunity, and if that person has the pressure, they certainly can rationalize it, and they certainly have been given the golden keys to actually go do it. So I think what’s changed is just more electronic means, and with AI, that one’s a scary one for me even in the field because I feel like we’re always playing catch-up, that they’re out doing something, and we’re trying to figure it out and how do we patch it? Think about an IT shop, right? They’re always trying to make sure we don’t get penetrated, and if they do, what can we do quickly to patch it, to fix it, to hire Sarah to make the PR to make the problem go away for us? But the same thing with AI. So AI scares me a little bit to be honest with you because I think it certainly is running faster than regulation, and I think it can outrun the good guys, so to speak, sometimes.

Sarah Snell Cooke: Yeah, AI is, it’s very scary. I’m just slightly pessimistic, and I think it’s gonna end up like Hunger Games. But again, I digress.

Deron Rossi: Let me write that down, that prediction. Today is 9/28.

Sarah Snell Cooke: You make a great point about AI too because the bad guys use it, but also the good guys use it. It can also help. But one of the things I was talking with somebody about not long ago is it’s kind of a cycle. The AI will create a prevention, but then it’ll also find the weakness. So then it’ll build the next… it’s like its own criminal and own sheriff.

Deron Rossi: Yeah. Hopefully they wake up in a good mood and are on the good side today, right?

Sarah Snell Cooke: I know. So do you think it’s gonna be an advantage, AI, in the long run, or disadvantage for people trying to prevent the crime anyway?

Deron Rossi: I think it’s gonna be both, and I know that’s probably not the right answer. But I look at it now, I’m doing this case that I told you about and I’m using AI to do things. I’m looking up stuff, trying to triangulate, is there a business relationship to this other relationship that they could be exploiting? How would I do that if I didn’t have AI? I’d have to read a lot and do a lot of queries on the internet. So it can help you do things quicker, faster than you’d be able to do. Those answers come out faster than you certainly can even run the cursor down to get to the bottom to see what did it just say to me. But to your point, I think if the brighter minds are using it in nefarious ways, then I think we’re gonna play catch-up. We’re gonna be trying to… hopefully there’s a free safety still back there that can make that last tackle and not let them get in the end zone.

Sarah Snell Cooke: Oh, and I guess I’ll introduce Freddy.

Deron Rossi: Oh, hey.

Sarah Snell Cooke: Here he is.

Deron Rossi: All right.

Sarah Snell Cooke: He’s been busy.

Deron Rossi: He’s cute. I didn’t hear anything, but he sure is cute. Oh, there’s a little hello. He said hello. That’s nice. Yes. Thank you. He’s saying hello all over the place.

Sarah Snell Cooke: So, there’s my new dog, my new executive assistant. Excuse me.

Deron Rossi: There you go.

Sarah Snell Cooke: What are some of the top methods that you’re seeing in internal fraud today, and how can they be prevented or detected? That’s a long question.

Deron Rossi: Yeah, that is. That is. So I still see some of the old school stuff with accounts payable. Think about where money comes out of: payroll, accounts payable, things like that, where people might be editing records and faking approvals. The funniest thing I had is where somebody… So in my old role, I had access to any record in the company, which meant everyone’s email too, if it was case involved. So I’d read these folks’ email, and I’d find the gold in their own email, in their own words, or on their own social media page where they’re bragging about, “Hey, look at this. I’m in Puerto Vallarta,” and I’d say, “Oh, I saw an expense account there. And by the way, you weren’t there for work. And you don’t need to put all that on the social media. Great, I’m gonna use that. Did you do this or did someone hack your Facebook account and put these photos that look just like you do in person on the system with that big white fruity drink in your hand?” Anyways, so with that I would be able to print things off and say, “You’re djr@us.ibm.com.” That used to be my ID. I’d slide it over and say, “That’s your ID, and this looks like it’s from your email, is it not?” “Oh, no, that wasn’t from me.” And it’s, “Oh, did you share your password with someone?” “Oh, no, no, we can’t do that at IBM.” “Well, how did this happen?” And to see the beads of sweat coming down and fidgeting in the chair and all that… some of that is still going on. People are still lying. That hasn’t changed either. But I think what’s different now, I think we’re a little better off in terms of fraud awareness in that this isn’t a new problem, right? And there’s a lot more reading out there, a lot more information that’s pushed out through the internet, through companies like yourself and others that do thought leadership. And I think that we’re smarter to it. I think one of the things that we could maybe do a better job of is just the continual training. There’s so many different trainings coming at everybody, and fraud is… “Oh, fraud, we don’t have to do that one,” they don’t have time for another class. But it’s funny, I did a fraud training on every employee in a Wisconsin utility, and they said, “Now you’re gonna have to do them on some odd times because they climb the poles when there’s a hurricane or a thunderstorm or a snowstorm, and we want 100% of the people to go through this.” And they asked me to do some other sessions. I said, “Absolutely.” That one really struck me as that person climbing that pole, freezing their butt off to put the power back on, they want that person to even know about fraud. That’s how important it was to them. And studies have shown from the ACFE, which is Association of Certified Fraud Examiners, probably the gold standard, platinum standard, that the more training you do, frauds are minimized, both the timing and the amounts. So do the training, have lower incidents in dollars of fraud. That one so impressed me that this utility went that far to do it. I said, “I’ll do these things at 3:00 AM if you want because this is great that you’re doing it.” So I think you can take that to the credit union industry and if we can push down more training, more awareness, because a lot of times 45% of the fraud cases are determined by a tip by an employee. So think if you don’t have a good tip line, think if you have a culture of fear in the credit union, “I’m not gonna call that tip line. They’re gonna know who I am, and I’m not gonna say anything. That person’s my second-line manager or whatever. They’re the director.” All those things, I think, are very fixable though. You can create that culture of openness and coming forward and knowing you won’t get retaliated against. If the CEO can push down the importance, “This is important to me, so it should be important to you.” All those things, I think, are little things that can be done cheaply and cost-effectively to help fight this fight.

Sarah Snell Cooke: And what if it’s the CEO?

Deron Rossi: Ooh.

Sarah Snell Cooke: Like in the Jacksonville Credit Union.

Deron Rossi: So what should boards… yeah, there was some people… what should boards be thinking about? What’s their responsibilities in this area? What should they be looking for?

Deron Rossi: They should be looking for how are we doing in our audits, both done internally and externally. Are we seeing trending? Asking those tough questions is probably more of the supervisory committee, which I call the first line of defense on that. But the board can’t sit back and say, “I’m not gonna worry about that. I got this supervisory committee over there.” Especially if you got a pain in the butt like me on the board that’s really in control. In any event, you get where I’m going with that, that it’s looking at the trends, looking at: Do we have a help line? Does anyone ever call it? I’ve called the help line before just to see if is someone gonna pick it up? Is someone gonna report me that I did it? And I actually did that to see. And it did come through. “Hey, why’d you call the help line?” I wanted to see if someone’s answering it because I don’t see any metrics that we’re really getting a lot of throughput there. So that means maybe we’re not pushing it, we’re not telling people on the POs that we send to our vendors, we should have that phone number or that email address to all the vendors so they know if there’s some hanky-panky going on, they can call in and report an issue. If you don’t get tips, almost half of your stuff, you got your head buried in the sand, right? So having an effective tip process, having that transparency, having that culture of openness, very important. I think the board’s responsible for setting that. Now, certainly the CEO’s the one that’s gotta take the ball and run with it, and it’s gotta be told to him or her that this is important, and then look for her or him to push that down through the team.

Sarah Snell Cooke: And so recently there, the Jackson Area Federal Credit Union, where the CEO allegedly took 90-some million dollars out of a credit union that’s probably about half the size as they were reporting because of the fraud… so where do things get missed? What needs more attention?

Deron Rossi: That’s a good one. There was a lot of misses probably on that one. I know that a lot of fingers are pointing at the regulator, and the regulator does come in, and I think they do ask some tough questions. I think a lot of times your CPA firm is really more at a high level, and people say, “Oh, that’s the CPA firm’s job to do.” Not really, and only 4% of the cases are found by that type of external audit. So if someone’s got all their cards down on that hand, that’s a, to use your betting analogy, that’s a pretty long shot bet right there. Oh, yeah. I think the NCUA could have done things better. I think there was maybe a little too much trust. And that’s a tough one, right? You want to trust the CEO. You have to trust the CEO. But at the same time, you gotta just look for what are those red flags. I did a case once where I got into the office, it was in the Midwest, a small office, and I heard the glass rumbling outside. I’m like, “What is that?” So I get up and look out, and there’s a Lambo out there. Lamborghini, sorry. Yeah. So I see a Lambo, and I see my guy get out of it, and he’s in his 20s. I said… now, as I told you before, I do have IBM. I had record availability to anything, so I knew what the person made. I’m like, “That ain’t a Lambo salary.” I took a picture of it, sent it to my son, who’s a car guy, go, “What is this? How much is this thing?” And he’s telling me, I’m like, “Ooh. Could have a red flag here possibly.” So I’m saying that, that’s an obvious one on that one, but those red flags are important. If the CEO’s never off, if their hands are in the mud there with everything, which is allowing them to then cover their tracks, all those types of things. So there’s probably not just one thing. There’s a lot of things, and I know, like I say, the regulators… some people are pointing the finger at them, and yeah, maybe they could have been a little tougher too. It’s hard to… everyone could be a Monday morning quarterback, so to speak, right? Hopefully, we do get the lessons learned from it without having to worry about pointing the fingers and just what factually can we learn from this to do better and push that out to everybody so everybody knows about it.

Sarah Snell Cooke: And what’s interesting is their corporate credit union I think was the one that actually originally reported it. I guess they did the processing of their truck cards or checks, whatever, and that’s how that got caught. So vendors, as you mentioned, are a big part of it, too.

Deron Rossi: Sure.

Sarah Snell Cooke: And of course we have this new podcast coming out with Andy Janning called The Overdrawn Podcast, and we’re looking at the costs and consequences of financial crime. And, that situation that he’s featuring in season one is a $6 million credit union where a CEO was able to pilfer $2 million out of it till he killed the credit union. Wow. So and, one of the things that I hear, and it seems logical, is that with some of the smaller credit unions, because they only have three employees, it can be a little bit easier to make things happen. That particular credit union I think had three or four employees and that was it, because the CEO—you can’t, they need to have access. Are there things that maybe smaller credit unions can do to help bolster their internal fraud defenses?

Deron Rossi: Yeah. Boy, that’s an excellent one. And by the way, that Overdrawn, I’m really excited to—you told me about that, and I read up on it, and I got a note to him right now to talk some more about that. That’s going to be awesome. Other than it’ll be sad when you see the profound effect that had on members and probably vendors and everyone that was involved. So that’s the downside of it, but I’m glad that he’s unveiling that and letting people see that.

So, but you point out a really tough one to answer, right? ‘Cause there’s three or four people, there’s gonna be lack of separation, and that’s where you hope that you can get someone with outside eyes to get in there and look. So they should be getting exams. To me, the NCUA should really be pretty focused on those situations where it’s probably more manual, more overlap in terms of the roles. And I don’t know if they are or they aren’t, ’cause I don’t have that availability or visibility. Sure. But, to me, that’s where they really need to look.

‘Cause I can feel for those folks trying to just keep the doors open and serve their membership, keep the hackers out, and still provide the essential services that they’re chartered to do. I don’t have a… unfortunately, I don’t have a magic bullet I can reach in my pocket and say, “Ah, if they do this, they’re gonna be all set.” Unfortunately, it’s not that easy. It’s just more of the same of good communication, being transparent, having audits done, and asking tough questions. That’s really key. It’s not that we don’t trust you, but you gotta be able to answer tough questions.

Sarah Snell Cooke: Yeah, for sure. So I really appreciate all your expertise today. I always allow my guests to have the final thoughts. What would you like to leave us with?

Deron Rossi: Sure. Unfortunately, and we hit on this earlier, this isn’t going away, so that’s the bad news here. People like me will still exist and be talking about this and trying to help out with the problem. So I think the more that we can push this down, I alluded to that earlier, so that everybody’s on the team. I did a presentation series called, Fraud Is A Team Sport, and it really is. Fighting fraud is a team sport. Hopefully creating it isn’t a team sport. It could be, but—

Sarah Snell Cooke: —Yeah.

Deron Rossi: Hopefully that team’s really small. But fighting it’s a team sport, and that’s why you really gotta propagate that messaging down to everybody and really kinda get everybody on board and realize it’s real. It’s not going away. Don’t say AI is gonna come in and eliminate it. I don’t think so. I think that can even make things worse. AI, you can say, “Make me an invoice today that looks exactly like this invoice,” and how are you gonna know? And it’s sent electronically. So it’s not like it came in the mail, and you slit open the envelope and can tell, “Oh, yeah, that’s the original invoice,” right? This stuff’s coming electronically. So it’s gonna be a bumpy ride still, and that’s why I think I wanna say everybody’s gotta get on the field for this one. And anytime I can talk about it and get people revved up about it, I’m kinda happy.

Sarah Snell Cooke: Love it. Love it. Yeah. Thank you so much. Appreciate your time today, Deron.

Deron Rossi: You bet. Anytime. You know that. So it was great catching up, too.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top