Bizuncto

Compliance

The assessment the failure-to-prevent-fraud defence rests on

Since September 2025 a large organisation can be liable when somebody associated with it commits a fraud meant to benefit it, and the defence is having had reasonable prevention procedures. Procedures nobody wrote down are hard to evidence two years later. This is where the assessment lives, with the date it next has to be looked at.

What happens to a request

  1. Risk owner Scopes it

    The business area or process, why it is being assessed now, and which associated persons are in scope — employees, agents, subsidiaries, suppliers acting on your behalf.

  2. Risk owner Assesses the risk

    Which fraud offences are in play, how the organisation would benefit, and likelihood and impact before any controls.

  3. Compliance Reviews the controls

    What already exists, who owns it, whether it has been tested, and the residual rating — plus training, communication and the reporting route.

  4. Executive sponsor Signs it off

    An approval only the sponsor can give, because an assessment approved by the person who wrote it is evidence of nothing.

  5. Automatic Comes back on its date

    Approved assessments reopen as Review due when the next review date arrives. The thing that makes procedures unreasonable is usually age.

It asks the question the offence turns on

Not "could somebody defraud us" but "how would the organisation benefit". Fraud against you is a different problem; this offence is about fraud committed for you, and an assessment that misses the distinction has assessed the wrong thing.

A gap is a route, not a footnote

Where due diligence, training or a control is missing, the assessment goes to Remediation with an owner and a target date, and comes back for sign-off. It cannot be approved by writing "to be addressed".

Ageing is the failure mode

Every approved assessment carries the date it is next due, and reopens itself then. What was reasonable two years ago is not a defence today, and nothing here depends on somebody keeping a reminder.

Every version is still there

Each answer keeps its history and the approval keeps its approver. When somebody asks what you knew and when, the answer is the record rather than a document whose last save date is all that survives.

It is evidence, not compliance

Whether your procedures are reasonable is a question for you and your advisers, and no software answers it. What this does is hold the evidence of having asked — the risk, the controls, the gaps, the sign-off and the review date — in a form somebody can be shown. Copy it and change the ratings, the offences and the review cycle to match your own risk framework.

Start with it
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.