My former boss (finance director) did this around 2001. We were paper ledger based but moving to online and yes bank statements were checked. No one suspected and he did it a number of ways.
Cash theft. We took large amounts of cash a couple of times a month (£30k to £60k plus across a number of outlets). No one liked our main boss and he (fin dir) played to this claiming he was so overworked he had to reconcile at home. We often told him he shouldn’t and he might not be insured. In this, was also the fact that staff at two or three outlets couldn’t add up for love nor money (true fact), so whatever they said they took would likely be inaccurate. Again we pushed for training, supervision, performance review which he always rejected. He was head of finance so we didn't question too deeply.
Company credit card. He and our main boss needed to sign off payments. However “for ease”, he’d present the main boss with his own list of transactions to save the boss (who wasn’t good at deep diving into detail) time. These would add up to the same amount as the real transactions and the boss would sign off the actual list without reading it (trusting it tallied with the one he had read). The real one included holidays, home renovations even our staff Christmas presents that we were told he’d bought out of his own pocket.
It equipment - he bought IT equipment that supposedly were site assets (various sites). They were for his home use.
False company. He set up a company with a very similar name to one we used and invoiced a few times for a few thousand which were paid.
Scanned fake invoices from existing suppliers. We had a three in one printer/fax/scanner - very posh then. He scanned the headers and footers of some of our genuine suppliers and marked them as settlements by credit card - payments going to a company account of another company he set up.
He flounced in a temper and we found all this within a couple of weeks of him going (without him there covering up it was pretty obvious when takings shot up).
The month before we had had a full audit and the auditors had picked up nothing.