What the TSL Diamond Fraud Teaches Us About Procurement Monopolies 謝瑞麟鑽石欺詐案對採購壟斷的啟示

In August 2026, a high-profile fraud case involving Tse Sui Luen (TSL) Jewellery concluded with a former procurement manager sentenced to nearly seven years in prison. Over a six-year period, this 25-year company veteran systematically stole 31 batches of diamonds worth over HK$11 million. The official narrative suggests that the fraud succeeded because three different suppliers bypassed standard inventory receiving procedures out of "established trust" for the senior manager, handing over the precious stones directly without entering them into the formal system.

However, framing this simply as an issue of misplaced trust misses the underlying structural failure. The core breakdown was a catastrophic lack of physical dual custody and segregation of duties, compounded by an environment that allowed a single individual to act as the ultimate gatekeeper for lucrative contracts. When one buyer holds the keys to a vendor's revenue stream, the dynamic is not trust, but rather commercial coercion. Vendors are forced into a "comply or die" position, bypassing controls not out of blind faith, but to secure their ongoing business relationship with the company.

In these coerced collusion scenarios, traditional textbook controls like three-way matching become entirely ineffective. The corrupt buyer and the compliant vendor will always ensure that the purchase orders, receiving notes, and invoices align perfectly on paper. Furthermore, the vendor rarely absorbs the cost of the stolen or misappropriated goods. Instead, that loss is quietly passed back to the company as a "fraud premium" hidden within inflated unit prices, degraded material quality (quality fade), or premium logistical fees. Ultimately, the company pays for its own stolen assets through silently bleeding margins long before any formal discrepancy is detected.

Solving this requires moving beyond surface-level paper compliance. Organizations must mandate strict physical dual-control (the four-eyes principle) for all high-value receipts and shift their audit methodologies toward commercial data analytics. Auditors need to continuously monitor vendor concentration risk, track price and margin benchmarking against market indices, and actively investigate static pricing in fluctuating markets.

Experience across the retail, FMCG, and manufacturing sectors shows that breaking this procurement monopoly requires establishing direct, unfiltered communication between vendors and oversight functions. One of the most critical steps a company can take is requiring major vendors to sign a comprehensive Vendor Declaration Form. This document explicitly outlines the vendor code of conduct and, crucially, provides instructions on how vendors can independently and anonymously contact Internal Audit or the Audit Committee if they face extortion or irregular requests. While this arrangement is rarely welcomed by procurement teams and often met with initial hesitation by vendors, it is an absolutely vital mechanism for protecting the company's commercial interests.

To make this sustainable, this control must be hardwired into the organization's Supplier Relationship Management (SRM) system. A vendor profile should not activate, and the central ERP should block all related purchase orders and payments, until this declaration is digitally signed and logged within the SRM. Looking ahead, the future of procurement auditing must treat the SRM not just as a vendor database, but as a mandatory compliance gateway. By integrating independent whistleblower channels directly into the digital vendor onboarding and renewal lifecycle, Internal Audit can finally dismantle the monopolies where procurement fraud thrives.




2026年8月,一宗涉及謝瑞麟珠寶(TSL)的備受矚目的欺詐案審結,一名前採購部經理被判處近七年監禁。在長達六年的時間裡,這名擁有25年年資的老臣子有系統地盜取了31批總值超過1,100萬港元的鑽石。官方說法指,欺詐之所以得逞,是因為三家不同的供應商基於對該名高級經理的「既有信任」,而繞過了標準的庫存接收程序,直接將貴重寶石交給他,而沒有將其記錄在正式系統中。

然而,如果僅僅將此歸咎於「錯付信任」,便會忽略潛在的結構性缺陷。核心的崩潰在於嚴重缺乏實體的雙重控制(Dual Custody)及職責分離,加上公司環境容許單一個人成為利潤豐厚合同的最終「守門人」。當單一買手掌握了供應商的收入命脈時,當中的動態就不是信任,而是商業脅迫。供應商被逼陷入「順從或出局」的困境,他們繞過內部控制並非出於盲目的信任,而是為了保住與公司的持續業務關係。

在這種受脅迫的共謀情境下,傳統教科書式的控制(如三單匹配 / Three-way matching)將變得完全無效。腐敗的買方與順從的供應商永遠會確保採購單、收貨單和發票在紙面上完美吻合。此外,供應商極少會自行承擔被盜或被挪用貨物的成本。相反,這些損失會作為「欺詐溢價」(Fraud Premium)悄悄轉嫁回公司,隱藏在被抬高的單價、下降的物料品質(品質縮水),或高昂的物流附加費中。最終,早於任何正式的賬面差異被發現之前,公司就已經透過不斷流失的毛利,為自己被盜的資產買單了。

要解決這個問題,必須超越表面上的紙本合規。企業必須強制規定所有高價值貨物的交收實施嚴格的實體雙重控制(四眼原則),並將其審計方法轉向商業數據分析。審計人員需要持續監控供應商集中度風險,追蹤價格與利潤率並與市場指數進行基準對比,並積極調查在波動市場中異常僵化的定價機制。

在零售、快消品(FMCG)及製造業的內部審計經驗表明,要打破這種採購壟斷,必須在供應商與監督部門之間建立直接、無過濾的溝通渠道。企業能採取的其中一個最關鍵步驟,就是要求主要供應商簽署一份全面的《供應商聲明書》(Vendor Declaration Form)。該文件明確列出供應商行為準則,更重要的是,它提供了詳細指引,教導供應商在面臨勒索或違規要求時,如何獨立、匿名地聯絡內部審計部或審計委員會。雖然這種安排往往不受採購團隊歡迎,供應商起初亦會有所猶豫,但這絕對是保護公司商業利益不可或缺的機制。

為了讓這種做法可持續發展,必須將此控制機制硬性植入企業的供應商關係管理(SRM)系統中。在供應商以電子方式簽署該聲明並記錄於 SRM 之前,其供應商檔案不應被啟動,中央 ERP 系統亦應自動攔截所有相關的採購單及付款。展望未來,採購審計的發展方向必須將 SRM 視為強制的合規關卡,而不僅僅是一個供應商資料庫。透過將獨立的舉報渠道直接整合到數碼化的供應商引入(Onboarding)和續約生命週期中,內部審計終能瓦解那些滋生採購欺詐的壟斷溫床。

Comments