Bizuncto

Compliance

Somebody tells you it happened anyway

A fraud risk assessment is what you did beforehand. This is the other half: a report arrives, and what happens next decides both whether it gets dealt with and whether anybody reports the next one.

What happens to a request

  1. Anyone Reports it

    Through the public form with no account at all, or to a case handler who writes it down. What is alleged, which part of the business, and a way to reach them only if they choose to give one.

  2. Case handler Triages it

    In scope or not, credible or not, who the conduct would have benefited, and whether the reporter is named, asking for confidentiality or not known at all — then whether it names anybody in the review chain, before they read it.

  3. Investigation lead Investigates

    Scope, evidence, who was spoken to. The reporter is kept informed and checked for detriment as the investigation runs, not afterwards.

  4. Audit committee Decides

    Substantiated, partly, not, or unable to determine — and whether it has to be reported to an authority. Closing it needs the committee, not the person who handled it.

  5. Case handler Acts on it

    Actions with an owner and a date, what controls changed, and which fraud risk assessment now needs revisiting.

Anonymous, or named, through one case

Switch the public form on and a report can arrive with no account behind it. It becomes the same record, triaged the same way — the difference is that who the reporter is becomes a question your team answers rather than one the form demands before it will accept anything.

The conflict question, asked first

Triage asks whether the report names anybody in the review chain, and who is handling it instead. It is the question a reporting process most often has no answer for, and the one that decides whether the process was worth having.

The reporter is checked on, not just recorded

Whether they were acknowledged, whether they have been kept informed, and whether there is any sign of detriment — each a required answer at the step where somebody could still do something about it.

Who benefited decides which problem this is

Fraud meant to benefit the organisation is the failure-to-prevent offence. Fraud against it is a loss. Both need handling and they are not the same case, so triage has to say which.

It feeds the assessment that missed it

Closing asks which fraud risk assessment needs revisiting. A report is the clearest evidence you have that a control did not work, and the place that matters is the document your defence rests on.

Anonymous if you switch it on, and off until you do

The public form starts off, because an area that strangers can write to should be one somebody decided to open rather than one that opened itself. Switched on, a report can arrive with no account and no name: the reporter is shown a reference once, and only a hash of it is kept, so nobody holding the database — us included — can turn up later claiming to be the person who reported. There is no way to recover a lost one, which is the same decision seen from the other side. Confidentiality and anonymity are different protections and this area asks about them separately: somebody can be known to you and still need their name kept out of the room.

Start with it
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.