Breaking Regulatory Compliance
Lugano Diamonds SEC Fraud Case: How $1B in Alleged Fake Revenue Beat the Control Stack
The Lugano Diamonds SEC fraud case shows how alleged fake revenue, inventory, and vendor records survived acquisition and audit controls.
Table of Contents
TL;DR
- The Lugano Diamonds SEC fraud case alleges more than $1 billion in fictitious revenue, hundreds of sham diamond investment contracts, fabricated invoices, and manipulated inventory records.
- The widely repeated $179 million is not an SEC fine. It was the acquisition-date value assigned to Lugano’s net identifiable assets; Compass Diversified later restated that value to $5 million.
- The alleged scheme survived a 2021 acquisition and years of audits even after a significant access-control deficiency was identified. The practical failure was not a missing policy. It was management override without a hard stop.
- Acquirers, CFOs, controllers, Internal Audit, and Audit Committees should test customer identity, cash purpose, inventory existence, user access, vendor pass-through payments, and closure of every management-override finding.
The Lugano Diamonds SEC fraud case is an unusually clean example of how impressive growth can be manufactured across several control layers at once.
On August 31, 2026, the SEC charged Mordechai Haim “Moti” Ferder, former CEO of Lugano Diamonds & Jewelry, and his controlled entity Simba IL Holdings LLC. The agency alleges that Ferder turned financing into sales, debt into revenue, repayments into inventory purchases, and nonexistent diamonds into audit evidence. That conduct allegedly caused Lugano and its publicly traded parent, Compass Diversified Holdings, or CODI, to recognize more than $1 billion of fictitious revenue from 2021 through 2025.
These are allegations in a civil complaint, not findings after trial. The SEC is seeking injunctions, disgorgement, prejudgment interest, civil penalties, and an officer-and-director bar against Ferder. No $179 million penalty has been imposed. The SEC’s September 1 litigation release explains that CODI originally valued Lugano’s net identifiable assets at $179 million when it acquired the business; the later restatement reduced that value to $5 million.
That distinction fixes the headline. The complaint describes warning signs across customer files, bank activity, inventory, user access, vendor payments, and audit interactions. Missing all of them means the evidence was never connected.
What the SEC alleges happened at Lugano Diamonds
CODI bought a 60% interest in Lugano Diamonds & Jewelry in September 2021. According to the SEC’s 41-page complaint in SEC v. Ferder, et al., CODI paid the sellers $103.7 million: $85.9 million to Simba and $17.7 million to three Ferder family trusts. Ferder retained influence through the remaining ownership and became CEO of the new CODI subsidiary.
The apparent performance after acquisition was spectacular. The SEC alleges that Lugano’s reported sales almost quadrupled. By the end of 2024, Lugano represented 21% of CODI’s reported revenue and 58% of its reported income.
The alleged economics underneath those numbers were very different.
| Alleged mechanism | How it appeared in the records | What the SEC says it really was |
|---|---|---|
| Diamond investment contracts | Jewelry revenue or reduction of accounts receivable | Short-term financing with promised returns, creating liabilities |
| Other financing arrangements | Sales, customer deposits, or receivable collections | Debt carrying interest or a “profit share” |
| Repayments to investors | Inventory purchases or supplier deposits | Ponzi-like payments routed directly or through vendors |
| Purported diamond transactions | Invoices, wires, receivables, and inventory entries | Fabricated or altered documents for diamonds not bought or sold |
| Customer concentration | Several of Lugano’s largest customers | Financiers whose funding was mislabeled as customer activity |
The complaint alleges that, after the acquisition, Ferder entered into at least 221 investment contracts that produced $205 million in cash but were used to record at least $428 million in revenue. It also alleges at least 171 other financing arrangements generated nearly $135 million in proceeds while Lugano recorded more than $180 million as revenue.
The liability side disappeared. Paragraph 24 of the complaint alleges unrecorded liabilities from the investment contracts and financing arrangements of $48 million at year-end 2022, $101 million at year-end 2023, and $170 million at year-end 2024, plus $27 million in accrued interest at the end of 2024.
This was not only a revenue-recognition problem. It was a completeness problem, an inventory-existence problem, a cash-classification problem, and a related-party and management-override problem.
The transaction trail was available
One example in the complaint shows why reviewing invoices alone would have failed.
The SEC alleges that Ferder offered an investor a half-interest in a 24.88-carat diamond ring. The investor would provide $1.08 million and receive $1.41 million about four months later—a stated 31% return. Ferder allegedly supplied a purchase invoice, wire evidence, a customer invoice, deposit evidence, and a diamond report.
The complaint says the package was fabricated. Lugano’s bank records and general ledger reflected only smaller, unrelated transactions with the named supplier and customer. The source systems did not agree with the deal file.
That mismatch is the control test:
- Start with the purported customer sale.
- Match the contract to an approved customer and independently confirmed contact.
- Trace the exact item through purchase, custody, inventory identifier, insurance, transformation, shipment, acceptance, invoice, cash, and any return.
- Compare the claimed wires with bank-originated records, not PDFs supplied by deal management.
- Test subsequent settlements: did the “customer” receive money back on a schedule that looks like principal plus return?
The failure mode is familiar to anyone doing control testing: five documents agree because one person created or controlled all five. Agreement inside a management-produced package is not independent corroboration. The practical techniques in this control testing and evidence guide apply directly—especially source independence and re-performance.
Three control failures mattered more than the fake invoices
1. Customer and financier identities were allowed to blur
The complaint alleges that three financiers were presented after acquisition as Lugano’s three largest customers. One purported customer supplied approximately $45 million in financing and was associated with about $53 million of recorded revenue; the SEC says only $233,800 was tied to actual sales. Another supplied about $31 million in financing and was associated with roughly $50 million in recorded revenue; only $180,000 allegedly related to actual sales.
A customer-master review should ask more than whether an entity exists. Finance and Internal Audit should identify whether the same counterparty:
- sends round-dollar funding unrelated to item-level invoices;
- receives principal-like or return-like payments;
- appears as both customer and supplier;
- settles other customers’ balances;
- funds transactions immediately before reporting dates;
- lacks normal delivery, acceptance, return, and sales-tax patterns; or
- has activity inconsistent with its stated business.
Ownership gets messy here. Sales owns the relationship, Treasury sees the cash, Accounting assigns the entry, and Legal holds the contract. The Controller should own the accounting conclusion, while Internal Audit or a controllership-review team independently tests unusual dual-role counterparties. No one should be able to resolve “customer or lender?” by changing a label in the ERP.
2. Management override was identified but not eliminated
This is the hardest allegation in the complaint to explain away as a clever fraud.
The SEC says CODI’s outside auditor identified a significant deficiency arising from Ferder’s ability to initiate, authorize, and conduct sales and inventory-purchase transactions in Lugano’s inventory system. The auditor was reportedly told his access had been restricted. The complaint alleges he nevertheless retained extensive access to create invoices, change pricing, and initiate and approve inventory transactions.
A remediation plan is not closure. Closure requires evidence from the identity platform and application itself:
| Required evidence | Closure test |
|---|---|
| Current role and entitlement export | Confirm prohibited create-and-approve combinations are absent |
| Access-change ticket | Match approved request, implementer, timestamp, and affected privileges |
| Authentication and transaction logs | Verify the user did not retain access through another account or delegated role |
| Emergency-access register | Reconcile every use to a ticket, reason, approval, and post-use review |
| Transaction sample after remediation | Confirm pricing, invoice, inventory, and approval events came from separate authorized users |
| Independent validation | Have Internal Audit or second line re-perform the test from raw system data |
For a founder-CEO or business president, “operational necessity” often becomes the exception that eats the control. If segregation is genuinely impossible, every transaction initiated by that executive needs an independent approval based on source evidence, plus a complete population review for unusual entries. The board or Audit Committee should see aging exceptions until the access is actually removed.
3. Inventory observation was treated as an appointment
The complaint alleges Ferder required inventory visits to be prescheduled, requested advance lists of the items auditors wanted to inspect, and insisted on attending. It further alleges that records were changed to show selected items had been loaned or transferred, empty packages or packages containing jewelry cleaner were shipped to support transactions, and loose gemstones were relabeled for inspection.
For portable, high-value inventory, observation design has to assume substitution risk. A stronger protocol includes:
- surprise or short-notice observations where permitted;
- auditor-selected floor-to-sheet and sheet-to-floor samples;
- frozen inventory populations and retained audit extracts;
- serial, certificate, weight, image, location, and custody matching;
- movement logs before and after count time;
- direct confirmation of consigned or off-site items;
- shipping-weight and carrier-event checks; and
- investigation of every item moved after the sample was selected.
Advance notice may be operationally necessary for secure premises. Advance disclosure of the exact sample is a different decision. If management controls both access to the site and the evidence population, the audit plan needs compensating procedures rather than accommodation by default.
Acquisition diligence cannot stop at audited numbers
The complaint alleges at least 28 undisclosed investment contracts generated more than $16 million before CODI’s acquisition. It also says target financials used in the deal understated liabilities from investment contracts by more than $20 million and other financing by more than $14 million.
That creates a distinct practitioner angle: financial diligence should test how revenue turns into cash and whether cash creates an obligation to return value.
For a target with concentrated revenue, an acquirer should:
- Confirm counterparties independently. Source contact details outside the target’s records and ask customers to confirm transaction purpose, item, amount, delivery, remaining obligation, side agreements, and whether they expect money back.
- Analyze gross and net cash by counterparty. A “customer” that receives recurring payments may be a financier, investor, rebate recipient, or related party.
- Test the largest and strangest growth. Sample from top customers, new customers, quarter-end entries, high-margin transactions, manual receivable reductions, and counterparties appearing in multiple master files.
- Search for undisclosed debt terms. Review emails, messaging, board materials, legal files, bank narratives, and personal guarantees for “return,” “profit share,” “interest,” “investment,” “advance,” or collateral language.
- Run post-close control onboarding immediately. Remove incompatible access, establish parent-level cash visibility, baseline counterparties and inventory, and retest acquisition representations against the first 90 days of activity.
CODI’s own May 7, 2025 Form 8-K said its Audit Committee opened an investigation into Lugano’s financing, accounting, and inventory practices after concerns were reported. It warned that 2024 financial statements should no longer be relied upon and that additional material weaknesses were expected.
CODI later stated in its 2024 Form 10-K/A filed December 8, 2025 that the investigation found deliberate fraudulent activity, control override, false documents, fictitious sales, inventory misrepresentation, and collusion with third-party providers. The filing says management concluded internal control over financial reporting and disclosure controls were ineffective as of December 31, 2024.
What should practitioners do in the next 30 days?
CFO and Controller — build the exception population
- List every counterparty that appears as customer, supplier, investor, lender, guarantor, or payment recipient.
- Flag journal entries and receivable reductions not tied to bank-confirmed customer settlement.
- Reconcile revenue to item-level fulfillment and cash; separately reconcile financing proceeds to recorded liabilities.
CIO and application owner — prove access, not policy
- Export current and historical privileged access for revenue, receivables, inventory, pricing, and payments.
- Identify create-and-approve conflicts, shared accounts, delegated roles, and emergency access.
- Preserve logs for any executive or founder with transaction capability.
Internal Audit — redesign confirmation and inventory tests
- Independently source counterparty contacts.
- Select samples without disclosing exact items early.
- Re-perform bank, inventory, shipping, and settlement matches from source records.
- Treat management obstruction, repeated delay, or fabricated confirmation evidence as a fraud-risk escalation—not a routine audit exception.
CCO or Head of Risk — split the remediation into testable findings
Do not create one item called “strengthen financial controls.” Open separate findings for incompatible access, counterparty classification, revenue evidence, unrecorded obligations, inventory existence, vendor pass-through payments, confirmation integrity, and management override. Each needs an owner, due date, interim control, dependency, validation method, and closure artifact.
The SEC’s recent Tricolor collateral case carried the same evidence lesson in a different asset class: management-generated records do not prove that an asset exists, is eligible, or sits where the ledger says it sits. The controls must reach independent source evidence.
If those gaps are currently scattered across audit workpapers and email, the Issues Management Tracker & Template gives the remediation team one place to assign, age, escalate, and validate them.
FAQ
Did the SEC impose a $179 million fine in the Lugano Diamonds case?
No. The SEC release says $179 million was CODI’s original acquisition-date value for Lugano’s net identifiable assets. The restatement reduced it to $5 million. The SEC seeks monetary relief, but the court had not imposed a penalty when this article was published.
Why is this case relevant outside the jewelry industry?
The alleged control failures are industry-neutral: debt recorded as revenue, hidden liabilities, concentrated customer risk, vendor pass-through payments, privileged-access conflicts, management override, unreliable confirmations, and inventory or asset-existence problems. Any acquirer or regulated company can face the same evidence failure.
What is the first control to test?
Start with management access. Determine whether any executive can create and approve revenue, pricing, receivable, inventory, or payment transactions. Then test the full population after the claimed remediation date to prove the restriction operated.
Who owns acquisition-control onboarding?
The CFO should own financial-control integration; the CIO should own access changes; the Controller should own accounting and close controls; Internal Audit should independently validate; and the Audit Committee should oversee high-risk exceptions. Corporate Development can coordinate the deal, but it should not validate its own diligence conclusions.
What evidence should close an internal-control finding?
Use raw entitlement exports, system logs, approved access tickets, transaction populations, exception dispositions, independent confirmations, and re-performance results. Policies, screenshots, or a management statement that access was removed are inputs—not sufficient closure evidence by themselves.
Source note: This article relies on SEC Litigation Release No. 26625, the SEC’s filed complaint, CODI’s May 7, 2025 Form 8-K, and CODI’s December 8, 2025 Form 10-K/A. The SEC’s allegations have not been adjudicated.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does the SEC allege in the Lugano Diamonds fraud case?
Did the SEC fine Lugano Diamonds or Mordechai Ferder $179 million?
Which internal control failure is most important in the SEC complaint?
What should an acquirer test when a target has concentrated customer revenue?
How should a compliance team track remediation from this type of control failure?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
SAR Confidentiality and Customer Communications: What Banks Can Now Say
The 2026 SAR confidentiality joint statement clarifies what banks can tell customers about fraud reviews, restrictions, and account closures.
Sep 2, 2026
Regulatory Compliance
The SEC's First Bespoke Crypto Offering Rule: What Regulation Crypto Assets Means for Your Compliance Program
The SEC's proposed Regulation Crypto Assets (File No. S7-2026-27) creates two new exemptions from Securities Act registration for token issuers — a $5M startup path and a $75M fundraising path. Comments are due ~October 20, 2026. Here's what crypto compliance programs need to assess now.
Sep 2, 2026
Regulatory Compliance
SEC Transfer Agent Rules Proposal: The New Risk Management, BCP, and Blockchain Control Mandate
The SEC transfer agent rules proposal adds risk management, BCP, compliance, recordkeeping, and restrictive-legend controls.
Sep 1, 2026