Embezzlement in California: Intent, Records, and Common Evidence Issues

White Collar Defense9 min read

Written by Boyadzhyan Legal Shield editorial team

Reviewed for legal accuracy by Knarik Boyadzhyan

Last substantively reviewed

An accountant and defense attorney tracing authorized payments across a ledger, approval email, and bank timeline
Topics

The hardest document to answer is the one with a single number on it, because there is nothing inside the number to answer. An audit schedule, an internal report, or the letter that came with the termination papers can compress months of ordinary work into one total, and a total is a sum, not a story. When an embezzlement accusation is built around a total like that, the first task is not to argue about the total in the abstract. Break it into transactions and identify the original source for each one.

One number may combine authorized expenses, disputed compensation, clerical mistakes, reversals, shared-account activity, and transactions the company alleges were personal. Treating unlike items as one story can hide who acted, what authority existed, where the property went, and what the records actually show.

California Penal Code sections 503 to 515 (opens in a new window) and CALCRIM No. 1806 (opens in a new window) frame an embezzlement accusation around entrusted property, fraudulent conversion or use for the accused's benefit, and intent to deprive. The embezzlement-versus-theft guide explains that broader legal distinction. The practical question, and the one you can start on now, is how to reconstruct authority, transaction history, source integrity, and competing explanations without altering the record after the accusation.

You answer transactions, not totals.

Begin by placing each questioned item on its own row and reviewing it with counsel against the original sources. That is how you find out which facts are documented, which are only asserted, and which records are still missing. Missing belongs on the list in writing: if the emails where someone approved a payment sit on a laptop or in an account you can no longer open, that is a record to identify, not a gap to fill in from memory.

You answer transactions, not totals.
FieldWhat to capture
Transaction identityDate, time, amount or property, account, reference number, and system
AuthorityJob duty, delegation, spending limit, approval requirement, and actual business practice
Initiation and approvalUser account, device, approver, workflow, override, and release step
Destination and benefitRecipient, account owner, vendor, item location, and alleged personal benefit
Contemporaneous purposeInvoice, receipt, contract, message, memo, calendar item, or stated business reason
Accounting treatmentOriginal coding, later edit, reversal, reimbursement, write-off, or audit adjustment
Source integrityNative record, export date, version history, metadata, and audit-log availability
Disputed explanationAuthorization, error, compensation, loan, duplicate, shared credential, or another identified issue

Keep the source next to the conclusion. If an internal report says “no approval,” note which approval sources were checked and which were unavailable. If the company says a payment was personal, identify the destination and the evidence of who controlled it. If your answer is that a supervisor said yes out loud, identify when, where, and whether any surrounding record supports or contradicts that account.

Do not net everything into one alleged loss figure too early. That discipline cuts both ways: a legitimate expense does not prove that an unrelated transaction was authorized, and a disputed item should not silently inflate the rest of the file. Separate facts first. Legal treatment follows.

Your job title rarely answers what you were allowed to do.

Authorization disputes are rarely resolved by a title or one handbook paragraph. You may have been allowed to prepare a payment but not release it, use a card only for defined expenses, or approve transactions only below a set amount. Several people may also have used the same register, login, key, or account, and an audit may not be able to tell from the login which of you was at the keyboard.

Compare the formal rules with the evidence of how the business operated before the accusation:

  • written policies, contracts, spending limits, and approval matrices;
  • emails, messages, meeting notes, and calendar entries showing approval given at the time;
  • recurring practices for reimbursements, advances, bonuses, loans, owner draws, petty cash, and vendor payments;
  • prior transactions handled the same way without objection;
  • system permissions and the dates those permissions changed;
  • later ratification, reversal, correction, or criticism; and
  • evidence that a rule was communicated to the person accused.

Actual practice does not automatically override a written rule. Nor does a written rule answer by itself what authority the person understood they had. The point is to reconstruct the setting that existed when the transaction occurred, not to apply a policy or explanation discovered later.

“The company paid” is not “you benefited.”

An audit may jump from “the company paid” to “the employee benefited.” Those are two findings with several steps between them, and the records should show each step. Identify who initiated the transaction, who released it, where the property went, who controlled the destination, and what benefit the accusation says you received.

A payment to a vendor, related business, family member, personal account, company card, or cash recipient raises different questions. A vendor payment might be legitimate, inflated, fictitious, duplicated, or connected to an undisclosed interest. A reimbursement might be unsupported, submitted twice, approved under a recurring practice, or reversed later. Do not force unlike transactions into one theory.

For noncash property, record identity and custody with the same care. Inventory numbers, checkout logs, serial numbers, shipping records, access badges, photographs, resale listings, and return records may show what happened to a particular item. A gross inventory variance does not identify by itself which item was in whose care or how it left the business.

Nothing in the ledger records what you meant.

No accounting entry announces a person's state of mind. Investigators may draw inferences from descriptions, supporting documents, destinations, repeated transactions, timing, changes to records, or interview answers. Each fact still needs context.

Some of what reads worst on a schedule may be bookkeeping rather than conduct. A description that looks false may have been a default system label. A repeated amount may reflect a recurring authorized expense. A delayed entry may follow ordinary month-end practice. Those explanations should not be accepted merely because they are possible, but neither should the audit's first interpretation be treated as the only one.

Trace a claimed approval back to its sender, date, scope, and original message, not to your memory of it. Compare a stated business purpose with the invoice, destination, and accounting history. Distinguish a contemporaneous instruction from a memo created after the accusation. The most useful sources show what you saw, did, and understood when the transaction occurred, not what you can explain about it now.

A screenshot is not the record underneath it.

An export, screenshot, PDF, or audit schedule may look complete while omitting hidden fields, filters, notes, attachments, reversals, deleted items, or historical permission data. A document like that is the output of somebody's choices about what to include. Preserve the source that allows the displayed result to be checked.

For an important record, keep:

  • the native file or system-generated export when available;
  • the date, time zone, filters, and fields used to create a report;
  • version history, change logs, deleted-item data, and permission history;
  • the person who can explain how the source is created and maintained;
  • the relationship among an entry, its attachment, approval, and later adjustment; and
  • an untouched copy separated from the working copy used for analysis.

A screenshot can help explain a screen, but it may not show who created the entry, when it changed, or which report settings were active. Keep the underlying data and the instructions needed to reproduce the view. Label any spreadsheet you build now as a later analysis, identify its sources and assumptions, and never use it to replace the original records.

Do not log into a personal account that is not yours, guess a password, or obtain records through access that has not been legally authorized. A work account you are no longer authorized to use counts. Preservation and collection must themselves be lawful.

Test the internal audit's method before adopting its conclusion.

An internal audit can identify useful patterns, but it is an analysis, not the underlying transaction history. Someone chose its inputs, and those choices are as testable as its conclusion. Ask what data the reviewer received, which dates and systems were included, how duplicates and reversals were handled, and what assumptions defined an “unauthorized” transaction.

Common points to test include:

  • whether a report used gross disbursements without accounting for reversals or returned property;
  • whether expenses, compensation, taxes, ownership interests, or vendor credits were treated consistently;
  • whether transactions were counted twice across a bank export and accounting report;
  • whether the audit inferred the user from a shared login;
  • whether a later policy was applied to earlier conduct;
  • whether missing records were treated as proof that no approval existed; and
  • whether the reviewer preserved source files and documented manual changes.

The aim is not to reject an audit because its conclusion is unfavorable to you. It's to separate source data, method, assumption, and opinion so each can be evaluated on its own terms.

If you paid something back, leave the original entry alone.

The instinct to make it right, to put the money back or fix the coding, is the one to be most careful with. A repayment, reversal, or correction should remain connected to the original transaction. Record when it occurred, who initiated it, what amount or property it covered, how it was described at the time, and whether it happened before or after the issue was discovered. The comparison guide explains why repayment does not decide the legal question by itself.

Preserve the original entry and the later event. Do not backdate a note, alter the first transaction, or describe a new payment as though it occurred earlier. A transparent chronology helps you more than a corrected ledger that no longer shows what happened.

Protect the source record before an interview or production.

An employer, investigator, auditor, or officer may ask for an immediate explanation, and the urge to give one is strongest when you believe the explanation is simple. A person who has seen only a summary may unintentionally adopt an incorrect date, amount, or assumption. Later records can make that first answer appear false or inconsistent even when the person was trying to help.

Do not alter records, try to make witnesses' recollections match, or send a long explanatory email before the transactions have been reconstructed. That email feels like the fastest way to end this, and it can become the version of your account that everything found later gets measured against. Preserve interview invitations, questions, audit summaries, termination papers, device notices, and communications with the company.

If a subpoena or records request has arrived, the business-records response guide explains the immediate document-first decisions without deciding the scope of any particular demand. If police seek a statement, the police-questioning guide addresses that separate decision.

Counsel can compare the accusation with the ledger and original sources, identify which conclusion depends on a summary or assumption, and help decide what should happen before an interview or production. You don't need an answer for every transaction before that conversation; you need the list. Initial consultations with Boyadzhyan Legal Shield are free and confidential, with no obligation to hire the firm. Request a consultation after gathering the questioned transaction list and the records you already have.

Continue reading