Compliance
Somebody tells you it happened anyway
A fraud risk assessment is what you did beforehand. This is the other half: a report arrives, and what happens next decides both whether it gets dealt with and whether anybody reports the next one.
What happens to a request
- Anyone
Reports it
Through the public form with no account at all, or to a case handler who writes it down. What is alleged, which part of the business, and a way to reach them only if they choose to give one.
- Case handler
Triages it
In scope or not, credible or not, who the conduct would have benefited, and whether the reporter is named, asking for confidentiality or not known at all — then whether it names anybody in the review chain, before they read it.
- Investigation lead
Investigates
Scope, evidence, who was spoken to. The reporter is kept informed and checked for detriment as the investigation runs, not afterwards.
- Audit committee
Decides
Substantiated, partly, not, or unable to determine — and whether it has to be reported to an authority. Closing it needs the committee, not the person who handled it.
- Case handler
Acts on it
Actions with an owner and a date, what controls changed, and which fraud risk assessment now needs revisiting.
Anonymous, or named, through one case
Switch the public form on and a report can arrive with no account behind it. It becomes the same record, triaged the same way — the difference is that who the reporter is becomes a question your team answers rather than one the form demands before it will accept anything.
The conflict question, asked first
Triage asks whether the report names anybody in the review chain, and who is handling it instead. It is the question a reporting process most often has no answer for, and the one that decides whether the process was worth having.
The reporter is checked on, not just recorded
Whether they were acknowledged, whether they have been kept informed, and whether there is any sign of detriment — each a required answer at the step where somebody could still do something about it.
Who benefited decides which problem this is
Fraud meant to benefit the organisation is the failure-to-prevent offence. Fraud against it is a loss. Both need handling and they are not the same case, so triage has to say which.
It feeds the assessment that missed it
Closing asks which fraud risk assessment needs revisiting. A report is the clearest evidence you have that a control did not work, and the place that matters is the document your defence rests on.
Anonymous if you switch it on, and off until you do
The public form starts off, because an area that strangers can write to should be one somebody decided to open rather than one that opened itself. Switched on, a report can arrive with no account and no name: the reporter is shown a reference once, and only a hash of it is kept, so nobody holding the database — us included — can turn up later claiming to be the person who reported. There is no way to recover a lost one, which is the same decision seen from the other side. Confidentiality and anonymity are different protections and this area asks about them separately: somebody can be known to you and still need their name kept out of the room.
Start with it