Skip to main content

CCS

Employee Fraud Losses: When Are They Tax-Deductible?

Share the Post:

“Delegation is an inevitable part of doing business; abdication is not.”

Delegating responsibilities is a business risk. Abandoning control is a management risk.

Public Ruling No. 4/2012 does not prescribe a fixed threshold, such as allowing a cash loss below 2% of turnover as a deduction while disallowing one above 5%.

Instead, the analysis requires consideration of the full set of circumstances:

  • Who committed the theft;
  • How the theft was carried out;
  • Why the person had access to the funds;
  • What action the company took after discovering the loss;
  • Whether the incident was a risk that could ordinarily arise in the course of that business; and
  • Whether the amount of the loss was so substantial that it exceeded the reasonably expected risks of that business.

Public Ruling No. 4/2012 remains listed in HASiL’s current Public Rulings list.

What Is an Inevitable Risk of Delegating Responsibilities?

The clearest examples are situations where the work cannot be performed unless the employee has access to money.

For example:

  • A cashier must handle cash;
  • A collection clerk must collect payments from customers;
  • A bank teller must handle customers’ funds; and
  • An accounts staff member must process payments as part of their duties.

Public Ruling No. 4/2012 itself provides examples where a cash loss occurs because the business must delegate certain responsibilities to a subordinate employee, who then steals or misappropriates the funds. In principle, such a loss may be regarded as incidental to the business.

Similarly, the Public Ruling provides an example involving an agent appointed to collect money who subsequently misappropriates it. Such a loss may also be allowable.

Why?

Because a business owner cannot personally:

  • Open the premises;
  • Receive payments;
  • Bank in the money;
  • Maintain the accounts;
  • Collect debts;
  • Perform reconciliations;
  • Close the premises; and
  • Audit their own work every night.

As a business grows, delegation becomes necessary.

The risk can therefore be understood in this way:

“To earn this income, I had to allow someone to access the money. The risk arose because of that ordinary commercial arrangement.”

This is closer to a commercial risk inherent in carrying on the business.

When Does It Become a Failure of Internal Control?

There is no provision in the tax law stating that a cash loss is automatically non-deductible simply because the company’s internal controls were inadequate.

That point should not be overstated.

However, weak internal controls can directly affect two important questions:

  1. Is the loss still a risk arising in the ordinary course of business?
  2. Has the loss become so substantial that it is out of proportion to the reasonably expected risks?

These are precisely the factors that Public Ruling No. 4/2012 requires businesses to consider.

The following three scenarios illustrate the distinction.

Scenario A: A Normal Delegation Risk

A company receives RM50,000 each day.

One employee acts as cashier, another banks in the money, the finance team performs the reconciliation, and the owner conducts a monthly review.

The cashier identifies a weakness in the system and steals RM30,000 over several weeks.

After discovering the fraud, the company:

  • Makes a police report;
  • Immediately suspends or terminates the employee;
  • Conducts a forensic review; and
  • Takes steps to recover the money.

In this situation, it is easier to regard the loss as a business risk.

The existence of controls does not mean that theft can never occur. Internal controls reduce risk; they do not eliminate human dishonesty.

Scenario B: A Significant Control Risk

The owner allows one Accounts Executive to:

  • Receive money;
  • Issue receipts;
  • Control the online banking system;
  • Perform bank reconciliations;
  • Make journal entries; and
  • Review their own work at the end of each month.

That employee steals RM1 million over three years.

The owner then asks:

“This is employee embezzlement, so the entire amount is tax-deductible, correct?”

The answer should be:

“Not so quickly.”

The tax authority may ask:

  • Why was one person able to handle the entire process from start to finish?
  • Why was the fraud not detected for three years?
  • Why was no one reviewing the bank reconciliation?
  • Why were there no maker-checker controls for transaction limits?
  • Why did the irregularities remain undetected for so long?

At this point, the dispute moves beyond the question of whether an employee stole money. It becomes a question of whether the business was exposed to a normal commercial risk, or whether the business itself had created an unrestricted withdrawal facility.

Scenario C: A More Difficult Case

The person who stole the money is:

  • The owner’s son;
  • A director; or
  • A member of senior management.

After discovering the fraud, the owner says:

“Let it go. He is family.”

The owner continues to employ the individual, does not make a police report and does not take steps to recover the money.

Public Ruling No. 4/2012 takes a strict approach in this area. It defines an “employee” as a subordinate employee and excludes an employee acting in a managerial capacity. It also expressly states that where the employee involved is a relative of the proprietor or employer, and the employer chooses to ignore the matter and continues to employ that person, the loss is not regarded as a trade loss.

In short:

Tax law may sympathise with the fact that you were the victim of theft, but it will not pay the bill simply because the person involved was a family member.

Why Is the KYH Case Particularly Interesting?

The circumstances in KYH were considerably more complex than an ordinary case involving a cashier stealing the company’s money.

The money taken was held in a client account.

The Revenue’s argument was a strong one:

  • The money was not the law firm’s own business income;
  • It belonged to the clients; and
  • If the taxpayer subsequently replenished the money, why should the taxpayer be entitled to a deduction?

HASiL’s 2025 ReveNews recorded this argument. The Revenue contended that money in the client account belonged to the clients and was not the taxpayer’s Section 4(a) business income. Accordingly, the replenishment of the client account and the related borrowing interest should not be deductible under Section 33(1).

Nevertheless, the SCIT ultimately ruled in favour of the taxpayer and set aside the assessments for YA 2012, 2014 and 2015.

This is instructive because tax deductibility cannot be determined solely by asking:

“Who did the money originally belong to?”

It is also necessary to consider why the loss occurred, what the business obligation was and the broader commercial circumstances.

However, a professional reservation should be noted. The ReveNews publication currently made available by HASiL is a case summary and does not set out the SCIT’s complete reasoning step by step.

Accordingly, KYH should not be interpreted broadly as establishing that every instance of employee theft involving client money will automatically be deductible once the law firm replenishes the funds.

That would go too far.

Client Accounts and Solicitor-Client Privilege

The background to KYH also touches on another important principle confirmed by the Federal Court.

In KPHDN v Malaysian Bar, the Federal Court explained that monies, documents and communications belonging to clients in a solicitor’s client account are, in principle, protected by solicitor-client privilege. Section 142(5) of the Income Tax Act does not completely override the privilege under Section 126 of the Evidence Act.

The Federal Court also emphasised that the Revenue cannot conduct a fishing expedition without a specific basis merely for the purpose of auditing a law firm’s income.

However, privilege is not a universal shield.

The Federal Court also stated that each particular document must be considered individually, and that the privilege under the Evidence Act is subject to exceptions, including the illegal-purpose exception.

Accordingly:

Privilege determines whether the tax authority may inspect certain information.
The burden of proof determines whether the taxpayer can establish its entitlement to the deduction.

These are two separate issues.

What Evidence Is Needed?

When asked whether stolen money can be claimed as a tax deduction, the practical answer should not be limited to the question:

“Was a police report made?”

A police report is only the first document.

The supporting evidence contemplated under Public Ruling No. 4/2012 may include:

  • The police report;
  • Bank statements;
  • The employee’s duties and authority;
  • The termination letter;
  • Board minutes;
  • Recovery actions; and
  • Other relevant evidence.

Businesses should also consider preparing:

Fraud chronology

When did the fraud begin? When was it discovered?

Delegation matrix

Why did the employee need access to the funds?

Internal-control evidence

What maker-checker arrangements, bank limits, reconciliations and review procedures were in place?

Quantum reconciliation

How was the amount of the loss calculated?

Recovery evidence

What steps were taken in relation to insurance claims, legal action, recovery from the employee and the freezing of assets?

The tax officer’s real question is not simply:

“Were you deceived?”

It is:

“Why should this loss be borne by your business income?”

A Practical Boundary

The distinction can be summarised as follows:

Where proper controls exist but an employee still manages to circumvent them and steal money, the loss is more likely to resemble a business risk.

Where the owner gives one person the keys to the entire treasury, all passwords and control over the reconciliations, and does not review the position for several years, the tax deduction becomes more difficult to explain.

The latter situation should not, however, be described as automatically non-deductible. Public Ruling No. 4/2012 does not establish such an absolute rule.

The correct legal analysis remains:

Person + Circumstances + Business nexus + Expected risk + Evidence

A Final Management Lesson

Trusting employees is part of management culture. Verifying their work is part of internal control. The two are not contradictory.

An owner may say:

“I trust him completely.”

The auditor may reply:

“That is good. Who performs the bank reconciliation?”

From a tax perspective, the key principle is this:

Tax law may recognise the risks that a business inevitably faces in carrying on its activities, but it may not necessarily recognise risks created after management controls have been abandoned.

In my view, the most valuable lesson from KYH for small and medium-sized enterprises is not that employee theft is automatically deductible.

It is this:

After fraud occurs, the question of deductibility ultimately returns to whether the loss was a genuine commercial loss arising from the operation of the business, and whether the taxpayer has sufficient evidence to prove the complete story.

As a related point, where a cash loss has already been allowed as a deduction and the amount is subsequently recovered through insurance, repayment by the employee or legal recovery, Public Ruling No. 4/2012 provides that the recovery will generally re-enter business gross income under Section 22(2) when it becomes receivable or is deemed to have been received.

委派是经营的必然,放弃控制却不是:员工盗窃损失何时可以扣税?

“Delegation 是做生意的必然;abdication 就不是了。”

委派职责是经营风险;放弃控制则是管理风险。

Public Ruling No. 4/2012 并没有规定一个所谓的神奇数字,例如“损失低于营业额的 2% 可以扣税,超过 5% 就不可以扣税”。

它要求根据整套事实进行分析,包括:

  • 谁实施了盗窃;
  • 盗窃是如何发生的;
  • 为什么有关人士能够接触这笔资金;
  • 公司在发现损失后采取了什么行动;
  • 事件是否属于该业务在正常经营过程中可能面对的风险;以及
  • 损失金额是否已经大到超出该业务 reasonably expected risks 的范围。

Public Ruling No. 4/2012 目前仍列在 HASiL 的 Public Rulings 清单中。

什么属于委派职责所必然产生的风险?

最典型的情况,就是有关员工如果不能接触资金,工作根本无法完成。

例如:

  • Cashier 必须处理现金;
  • Collection clerk 必须收取客户款项;
  • Bank teller 必须处理客户资金;以及
  • Accounts staff 因工作需要必须处理付款事宜。

Public Ruling No. 4/2012 本身就举例说明,如果 cash loss 是因为业务必须把某些职责委派给 subordinate employee,而该员工因此盗取或挪用款项,原则上,这种损失可以属于 incidental to the business。

同样地,Public Ruling 也举例说明,企业指定 agent 负责收款,而 agent 之后将款项挪用,这类损失也可能属于 allowable loss。

为什么?

因为企业老板不可能亲自:

  • 开门;
  • 收钱;
  • Bank in;
  • 做账;
  • 追债;
  • 对账;
  • 关门;以及
  • 每晚自己 audit 自己。

企业发展到一定规模后,delegation 是不可避免的。

因此,这种风险可以这样理解:

“为了赚取这份收入,我不得不让某个人接触这笔钱;而正因为这个正常的商业安排,风险发生了。”

这就比较接近 commercial risk inherent in carrying on the business,即经营该项业务所固有的商业风险。

什么时候开始变成企业自己的内控问题?

税法并没有一条规定说:“只要内控不好,cash loss 就一律不能扣税。”

这一点不应被过度延伸。

但是,薄弱的 internal control 会直接影响两个重要问题:

  1. 这是否仍然属于 ordinary course of business 的风险?
  2. 损失是否已经大到 out of proportion to the reasonably expected risks?

这两项正是 PR 4/2012 明文要求考虑的因素。

以下三个场景可以说明其中的区别。

场景 A:正常的委派风险

公司每天收取 RM50,000。

由 Cashier 负责收钱,另一名员工负责 bank in,Finance 负责 reconciliation,而老板每个月进行 review。

Cashier 找到系统中的漏洞,在几个星期内连续偷走 RM30,000。

公司发现后:

  • 报警;
  • 立即停职或解雇有关员工;
  • 进行 forensic review;以及
  • 采取行动追讨款项。

在这种情况下,我会比较容易认为,这属于 business risk。

有 internal control,并不代表永远不会发生盗窃。Internal control 的作用是降低风险,而不是消灭人性。

场景 B:开始变得危险

老板让一名 Accounts Executive 同时负责:

  • 收钱;
  • 开 receipt;
  • 控制 online banking;
  • 做 bank reconciliation;
  • 做 journal entry;以及
  • 在月底 review 自己的工作。

这个人连续三年偷走 RM1 million。

老板问:

“这也是 employee embezzlement,所以全部都可以扣税,对吗?”

我会回答:

“先不要那么快。”

因为税局很可能会问:

  • 为什么一个人可以从头做到尾?
  • 为什么三年都没有人发现?
  • 为什么 bank reconciliation 没有人 review?
  • 为什么 transaction limits 没有 maker-checker?
  • 为什么这些异常这么久都没有被发现?

这时候,争议就不再只是“员工偷了钱”。

问题会逐渐变成:

企业面对的是正常商业风险,还是企业自己制造了一个不受限制的提款机?

场景 C:更加困难的情况

偷钱的人是:

  • 老板的儿子;
  • 董事;或
  • Senior management 成员。

老板发现后却说:

“算了啦,自己人。”

之后继续聘用有关人士、不报警,也不追讨款项。

PR 4/2012 在这一点上采取了较严格的立场。它把“employee”定义为 subordinate employee,并排除 managerial-capacity employee。

此外,如果涉案员工是 proprietor 或 employer 的亲属,而老板选择忽略事件并继续聘用该员工,PR 也明确表示,这类损失不被视为 trade loss。

所以可以这样说:

税法可以同情你被偷,但不会因为偷钱的是“自己人”,就顺便替你埋单。

为什么 KYH 特别有意思?

因为 KYH 的情况,比一般 Cashier 偷公司钱复杂得多。

被偷走的是 Client’s Account 里的钱。

Revenue 的论点相当有力:

  • 那不是律师楼自己的 business income;
  • 那是客户的钱;以及
  • 如果之后是 taxpayer 自己把钱补回去,为什么应该让 taxpayer 享有 deduction?

HASiL 的 2025 ReveNews 记录了这项论点。Revenue 认为,client-account money 属于客户,并不是 taxpayer 的 Section 4(a) business income。因此,补回 client account 的款项以及有关借款利息,不应根据 Section 33(1) 扣除。

可是,最后 SCIT 判 taxpayer 胜诉,并撤销了 YA 2012、2014 及 2015 的 assessments。

这点非常具有教育意义,因为 tax deductibility 不能只问:

“这笔钱原本是谁的?”

还必须考虑:

  • 损失为什么发生;
  • business obligation 是什么;以及
  • 整体商业环境如何。

不过,这里需要加上一个专业保留。

目前 HASiL 公布的 ReveNews 只是案件摘要,并没有完整列出 SCIT 每一步的 reasoning。

因此,我不会把 KYH 扩大解释成:

“以后所有员工偷走 client money,律师楼补回去后,都一定可以扣税。”

这样会讲得太远。

Client Account 与 solicitor-client privilege

KYH 的背景也涉及另一个 Federal Court 已确认的重要原则。

在 KPHDN v Malaysian Bar 一案中,Federal Court 说明,律师 client account 中属于客户的 monies、documents 及 communications,原则上受到 solicitor-client privilege 保护。

Section 142(5) of the Income Tax Act 并没有整体推翻 Evidence Act Section 126 所保障的 privilege。

Federal Court 也特别强调,Revenue 不能仅仅为了 audit law firm’s income,而在没有具体依据的情况下进行 fishing expedition。

但是,privilege 也不是律师楼的“万能隐身斗篷”。

Federal Court 同时指出,必须逐项审查 particular document;而 Evidence Act 下的 privilege 本身也存在例外,包括 illegal-purpose exception。

因此:

Privilege 决定税局能不能查看某些资料。
Burden of proof 决定 taxpayer 能不能证明自己有权享有 deduction。

这是两个不同的问题。

需要准备什么证据?

当有人问“员工偷了钱,可以扣税吗”,实务上的答案不能只停留在:

“有没有 police report?”

Police report 只是第一份文件。

PR 4/2012 所要求考虑的 supporting evidence 可以包括:

  • Police report;
  • Bank statements;
  • 员工的职责及权限;
  • Termination letter;
  • Board minutes;
  • Recovery actions;以及
  • 其他有关证据。

我也会建议企业准备以下资料:

Fraud chronology

欺诈什么时候开始?什么时候被发现?

Delegation matrix

为什么这个员工需要接触资金?

Internal-control evidence

当时有哪些 maker-checker 安排、bank limit、reconciliation 及 review 程序?

Quantum reconciliation

损失金额是如何计算出来的?

Recovery evidence

企业是否提出保险索赔、采取法律行动、向员工追讨,或申请冻结资产?

因为税务官真正想知道的,不只是:

“你有没有被骗?”

而是:

“为什么这笔损失应该由你的 business income 来承担?”

一个非常现实的界线

我会这样总结:

有控制,但员工仍然突破控制并偷走款项——这比较像 business risk。

没有控制,老板把整个金库的钥匙、所有密码以及对账权全部交给同一个人,而且几年都没有检查——这时 tax deduction 就开始变得难以解释。

不过,我不会说后一种情况 automatic non-deductible。

因为 PR 4/2012 并没有设下这样的 absolute rule。

正确的法律分析仍然是:

Person + Circumstances + Business nexus + Expected risk + Evidence

给管理层的最后一个提醒

信任员工是管理文化;验证员工的工作是内部控制。两者并不冲突。

老板可以说:

“我很相信他。”

Auditor 则会问:

“很好,那 bank reconciliation 谁做?”

从税务角度,最值得记住的是:

税法可以承担企业经营过程中必然面对的风险,但不一定愿意承担企业放弃管理后自己制造出来的风险。

因此,我认为 KYH 给中小型企业最有价值的启示,并不是:

“员工偷钱也能扣税。”

而是:

“发生 fraud 以后,能不能扣税,最终仍然要回到:这是不是经营这门生意所产生的真实商业损失,以及企业有没有足够证据把整个故事证明出来。”

顺带一提,如果某项 cash loss 已经获得 deduction,而日后通过保险、员工偿还或法律追讨追回款项,PR 4/2012 规定,有关 recovery 一般会在成为 receivable 或 deemed received 时,根据 Section 22(2) 重新计入 business gross income。