Patrick Bhunu
SENIOR management in a business organisation has a fiduciary duty to its shareholders and other stakeholders for taking responsible steps in ensuring that the organisation is not exposed to the risk of fraud perpetrated by either staff members, suppliers or customers.
Management should maintain a robust control mechanism to both prevent and detect fraud. One of the control measures that the organisation can put in place is the fraud policy. This is a document which needs to be brought to the attention of employees of the organisation. It is signed and approved by the senior management in its quest to give directions on how to prevent, detect and report fraudulent activities. The document also regulates the powers of particular individuals within the organisation.
When crafting the fraud policy, the management should clearly state the purpose of the policy document, state irregularities and suspected irregularities, actions that can be considered as fraudulent, duties and responsibilities of individuals or departments, reporting procedure and the investigations process.
The primary purpose of the fraud policy is to give a clear definition of what the organisation regards as amounting to fraud, gives a summary to employees of their respective responsibilities for identifying exposures to fraudulent activities when they occur. The policy document also provides guidance to employees as to which course of action they should take in the event that they suspect any fraudulent activity and it also gives laid down responsibilities for conducting investigations in fraud related activities.
Guidelines are also given to outline the mandatory duty of reporting fraud by the employees or any of the stakeholders of the organisation. It is important to note that reporting of fraud is handled in different ways by different organisations depending on the organisational culture and the type of shareholders or prospective investors of the organisation. Some organisations do not advocate for police involvement in every fraud case perpetrated against them by their employees or outsiders. They do not want to bring such cases under public scrutiny, not because the management will be trying to cover up for the culprits, but because the organisation will be trying to protect its image and reputation.
No investor would be comfortable in ‘‘seeding’’ in an organisation which is always prone to fraud as this would lead to losses and eventually liquidation and the investor ultimately fails to get a return on their investment.
The nature of irregularities or suspected irregularities are those actions that are perpetrated by employees or outsiders and may be prejudicial, both in actual or potential terms, to the organisation. Some of the irregularities are expected to be picked up by employees during the course of their duties. All these should be clearly explained in the policy document.
Actions that constitute or that an organisation consider as constituting fraud should be explicit on the fraud policy document.
It is quite true that some employees commit fraud without knowing that what they are committing is fraud, especially during the course of their duties. To this end, it is imperative that the organisation lists and explains actions what it deems to be fraudulent in nature.
The most common types that may apply to all the organisations, regardless of size and culture, include, and are not certainly limited to, the ordinary fraud that we all know where an employee, for example, alters invoices and steals money from the company, conflict of interest, ghost workers in regards to the Human Resources department, ordinary theft, money laundering, generating false reports, non-procedural tendering and purchasing processes or engaging in any conduct which may be prejudicial to the organisation.
In one of the paragraphs above, I indicated that one of the purposes of a fraud policy document is to give duties and responsibilities to respective staff members. Holistically, it is the management which is primarily responsible for preventing and detecting fraud through the implementation, documentation and monitoring of effective internal control systems.
Internal control systems are designed to support a wide variety of goals that are essential to a healthy organisation. They help in minimising losses through fraud, mismanagement, loss of trust and resources. In a more basic way, it is the duty of each and every employee to prevent, detect and report fraud. In some organisations the internal audit function is also given the responsibility of preventing, detecting and reporting of fraudulent activities.
Timelines should be drawn in reporting suspected fraud cases. Caution should be made not to alert the fraudster or suspected fraudster before the report has been made. Reports should be made to the respective person or persons according to the requirements of the organisation.
The policy document should specify who is responsible for investigations. Some organisations prefer to use their own internal loss control personnel while others prefer independent outside investigators depending on the nature and merit of the case. It is all good so long this is well documented in the policy. There should also be mention of procedure on the involvement of experts such as auditors and valuators in the investigations. All the work done by investigators, including audio recordings, should be well documented.
However, because organisations differ, fraud policy documents are also bound to differ here and there but what has been highlighted here are the basic areas that organisations need to consider when crafting fraud policies and procedures documents. A good policy should be clearly visible and understood by everyone in the organisation. It should not be secretive or selective. Thus, it should be established, followed, monitored and reviewed. This cycle should be repeated again and again throughout the life of the organisation.
Feedback on [email protected]
sms on 0716532802.





