Written by Arlene Clapham, Risk and Assurance Manager at Sayer Vincent
It’s Charity Fraud Awareness Week and with the cost-of-living crisis impacting individuals and charities, there’s arguably never been a more critical time for organisations to rethink their risks and how they may be susceptible to fraud.
This year’s event comes at a time of economic crisis and, in times of austerity fraud typically rises. Additionally, many organisations are still re-shaping and rebuilding following the global pandemic, often changing their ways of working, which can make them more vulnerable.
The Fraud Advisory Panel has suggested charities and organisations providing services and supporting local communities may be especially vulnerable to fraudsters attempting to exploit current national and global crises to carry out fraud and cybercrime.
Fraud escalated during the pandemic
Fraud didn’t disappear during the pandemic – far from it. A report from BDO and the Fraud Advisory Panel[i] highlighted that 65% of respondents agreed or strongly agreed the pandemic had increased the risk of fraud to their charity, and 52% believed that the pandemic and remote working made it more difficult to manage the risk of fraud to their charity.
In recent months, we have also seen several cases of fraudsters taking advantage of natural disasters and the war in Europe to exploit people. While the public engagement in these campaigns has enabled the sector to respond quickly to the needs of those affected, they have also provided increased opportunity for fraudsters to impersonate charities, undertake scams and prey upon the good will of donors.
Externally, the risk of fraudulent campaigns that may “appear” to be legitimate is increased, from local events to online giving platforms, in effect diverting funds away from the cause and towards fraudster.
Internal controls need to be reassessed
While most people are honest, internal fraud is equally an issue for charities and in times of financial hardship people’s motivations will be stronger, so charities need to be alert.
Fraud can range from claiming a few extra miles on expense claims or setting up fictitious suppliers to make payments to an employee’s bank account.
Most people who commit fraud in charities are not career criminals. They are often trusted staff with no criminal history, but they commit fraud because the opportunity is there – arguably this is more likely to happen in times of austerity.
Internal risks can also emerge from organisational restructures. During the pandemic, we saw more charities merge, make redundancies, or restructure parts of their organisation to reduce their costs and any such changes can impact the effectiveness of internal controls which are designed to prevent fraud.
With any restructure, it’s good practice to ensure procedures remain fit for purpose and reflect the current ways of working. This internal critique will expose obvious control gaps, such as segregation of duties.
New risks can also emerge when organisations recruit new staff members and particularly if a position lies vacant before it is filled. As many organisations have been struggling to fill roles this year, such gaps could weaken an organisation’s internal controls and open them up to greater risks.
Another thing for charities to review is their processes for reporting serious incidences and check they are still fit for purpose. According to The Charity Commission, whistleblowing disclosures about charity wrongdoings dropped by 35% last year. While this could mean less fraud being committed, it could also be a red flag that internal controls are weaker, and that whistleblowing isn’t being encouraged and the reporting of serious incidences isn’t taking place.
Conclusion
The cost-of-living crisis is heightening fraud risks faced for charities and not for profits – both in terms of external and internal threats.
This year’s Charity Fraud Awareness week is the ideal time and reminder for organisations to reset – to take stock, reflect and review all their processes and controls to ensure they are as robust as they can possibly be.
Here are some key questions that can help your organisation determine fraud risk.
- Are fraud risk assessments carried out regularly?
- Are fraud risks regularly discussed and what are the outcomes from the discussions?
- Do we review our control mechanisms regularly?
- Who is responsible for reviewing these when there are changes to the ways of working or to the roles that are contributing to the control environment (arising from restructures of recruitment gaps)?
- Have we identified key roles, and do we have succession plans?
- Are the oversight arrangements effective? How do we know?
- How do we become aware of potential frauds?
- What do we do with the information?
- How do we investigate potential frauds?
- Who investigates?
- How do we communicate the findings and the learning?
- Can we use our data better to support the detection of potential fraud as early as possible?
- How do we demonstrate fair and consistent process for responding to fraud?
References