Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Wirecard's Collapse: Six Control FailuresThird-Party Risk Management
5 min readFor Compliance Officers

Wirecard's Collapse: Six Control Failures

The Wirecard fraud wasn't a sudden explosion. It was a slow-motion collapse of every control layer that should have stopped it. By the time investigators confirmed that €1.29 billion in escrow accounts didn't exist, the company had been fabricating profits for two decades.

Dan McCrum, the Financial Times journalist who exposed the scheme, identified six specific control failures that allowed CEO Markus Braun and his team to sustain the fraud. These failures highlight gaps in how your team might design compliance programs, audit third-party relationships, and protect whistleblowers.

What the Wirecard Investigation Revealed

McCrum's investigation, which led to the 2020 collapse of a €20 billion DAX company, showed how fraudsters exploit assumptions in standard compliance frameworks. The Munich Public Prosecutor's Office even investigated McCrum in 2019, showing how aggressively the company defended its fiction. That investigation was closed in September 2020 with no evidence of wrongdoing.

This wasn't about sophisticated technology or clever accounting. It was about deliberate complexity, intimidation, and the misuse of compliance infrastructure.

Key Control Failures

1. Structural Opacity as Strategy

Wirecard created a confusing network of partner companies and third-party processors. Auditors accepted the explanation that these entities processed payments on Wirecard's behalf and that commissions sat in escrow accounts. The complexity itself became the defense: too many moving parts for anyone to trace the actual cash flows.

Your controls should flag complexity that serves no operational purpose. When a vendor relationship requires multiple intermediaries, cash flows through unusual jurisdictions, or ownership structures obscure beneficial owners, you're looking at potential concealment. AS 2201 requires auditors to understand the business rationale for related-party transactions. Apply that skepticism to your vendor risk assessments.

2. Weaponized Compliance Investigations

Wirecard operated an anonymous reporting system but used it to identify and monitor employees who raised concerns. Whistleblowers who reported internally received no meaningful follow-up. Those who escalated externally faced retaliation disguised as investigation.

Your whistleblower hotline isn't effective if the same executives accused in reports control the investigation process. Segregate intake, investigation, and remediation. Route reports of C-suite misconduct directly to the board audit committee or an independent third party. Document every report and every step of your response. The Sarbanes-Oxley Act requires audit committees to establish procedures for receiving complaints about accounting or auditing matters. Make sure yours can't be circumvented by the people being reported.

3. Counter-Attack as Cover

When McCrum published his findings, Wirecard didn't address the substance. They filed criminal complaints, hired private investigators, and constructed elaborate narratives about market manipulation and short-seller conspiracies. The German authorities investigated the journalist, not the company.

This pattern should trigger immediate escalation in your third-party due diligence. When a vendor responds to audit findings or compliance questions with legal threats, PR campaigns, or accusations against the auditor, you're seeing a red flag that transcends the original concern. Document the response itself as a separate risk indicator.

4. Reputation as Camouflage

Wirecard hired prestigious law firms, compliance consultants, and PR agencies, using those relationships as proof of legitimacy. McCrum noted that criminals hide behind the reputations of others, and professional services firms can be used to obscure fraud rather than prevent it.

Your vendor risk profile should assess not just what controls exist, but whether they're genuinely independent. A third-party attestation from a firm that also provides consulting services to the same vendor isn't independent. A compliance program designed by consultants who report to the CFO under investigation isn't independent. The COSO Internal Control-Integrated Framework emphasizes the importance of objectivity in monitoring activities. Apply that principle to how you evaluate vendor-provided assurances.

5. Diffusion of Responsibility

The bystander effect explains why multiple parties can observe the same red flags without acting. Each assumes someone else has already verified the facts. Auditors assumed regulators were monitoring. Regulators assumed auditors were testing. Banks assumed the DAX listing meant rigorous oversight had already occurred.

Your control objective mapping should explicitly assign verification responsibilities. Who confirms that vendor financial statements are accurate? Who validates that escrow accounts contain the reported balances? Who tests whether subcontractors actually exist? If the answer is "we rely on the auditor's report" or "we assume the vendor's compliance team handles it," you've identified a gap.

6. Scale as Immunity

By the time Wirecard reached a €20 billion market cap, it had become too big to question. Investors had made substantial returns. Ernst & Young had signed off on the financials for years. The company was more valuable than Deutsche Bank. Who would challenge that success?

Your ongoing vendor monitoring should intensify as relationships grow, not relax. The vendor that now processes 40% of your transactions or holds significant customer data deserves more scrutiny than it did at contract signature, not less. Materiality should trigger enhanced due diligence, not reduced oversight.

What This Means for Your Compliance Program

These six failures share a common root: controls that looked sufficient on paper but lacked genuine independence, skepticism, and accountability. Wirecard had an anonymous reporting system, external auditors, compliance consultants, and regulatory oversight. None of it worked because each layer was either compromised or assumed someone else was doing the actual verification.

Action Items by Priority

Immediate:

  • Audit your whistleblower intake process. Confirm that reports alleging C-suite misconduct bypass those executives entirely and route to the board audit committee or independent counsel.
  • Review your vendor risk profiles for any third parties with complex ownership structures, multiple intermediaries, or unusual cash flow arrangements. Flag these for enhanced due diligence.

This quarter:

  • Map your control objective verification responsibilities explicitly. For every control you rely on (vendor SOC 2 reports, third-party attestations, audit opinions), document who actually tests the underlying facts and how often.
  • Establish a protocol for escalating vendor responses that include legal threats, PR campaigns, or accusations against your audit team. Treat the response itself as a risk indicator.

This year:

The Wirecard fraud succeeded because multiple sophisticated parties made the same assumption: someone else must be checking. Your job is to make sure that assumption is never true in your organization.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like