On my way to the dentist today, what should have been a 15-minute drive took nearly 30. Not a biggy, but by the third set of temporary traffic lights, it was a little tedious. At lights No.1, nothing was visibly happening - one chap in high-vis was looking into a drain on the side of the road as two others vaped and chatted. So far, so standard. No.2 was more impressive - a hole around 1.5m deep and wide enough to require wooden beams bracing the earth (stopping it from collapsing in). Okay, looks serious—light No.3, nothing; just some bollards cordoning off a bit of road.
As I waited, it struck me that many of our colleagues, especially those incentivised to get things done quickly (business development, deal teams, operations), must see a lot of what we do (risk management) as pointless roadworks. Now, I know you (we) all take great care not to be No.3 (absent, unreachable, pointless). Still, sometimes we will be No.1, examining a drain (checking that the shareholder in a proposed deal isn’t a government crony or those suspiciously identical payments to an advisor sourcing new business).
I used some rough data on a deal that’s just closing (yet another multi-country renewable energy project, providing power not to the grid but to large private clients: manufacturing, real estate, mining, etc.). We have some rough metrics: a ~$80m investment, for which my direct client is liable for roughly half, across nine countries, with a 5-7 year exit envisaged. With that data, could we:
A) Model the costs of NOT managing integrity risks (fraud, principally); i.e. not fixing the road. B) Generate some imagery more compelling than your usual “Public works from XX June to XX August, expect delays.”
The modelling
Data from the Association of Certified Fraud Examiners’ 2024 Report to the Nations, analysing 1,921 cases across 138 countries, reveals that organisations lose a median of 5% of their revenue to fraud annually. In some of the sectors the investee would serve, like mining, this figure climbs to 6.4% (for infrastructure, some estimates indicate that procurement fraud alone can consume 8% of spending).
I feel the 5%-8% figure appears a touch unbelievable, so I wrote a complex prompt (factoring indirect costs like management time, ESG valuation discounts, and increased capital costs) for one of the better AI reasoning tools, which gave me the following scenarios across the term of the investment (A is the one we’ll run with):
Scenario A (Early Detection): $4.7 million total cost (11.6% of investment) Scenario B (Significant Fraud): $17.9 million total cost (44.6% of investment) Scenario C (Major Scandal): $64.3 million total cost (160.8% of investment)
Most painfully, for your move-fast-and-break-things colleagues, after an incident like this, the cost of compliance skyrockets. For this deal, with their current and proposed operations, a conservative quote for due diligence alone (for the remaining deal term) might range from $500,000-$1m (depending on who they choose).
Flipping that on its head, an investment of $500,000 in integrity risk management across the deal term (let’s take the shorter timeframe of 5 years for lazy calculations) suggests that a $100k per annum integrity risk budget would achieve an ROI of 840% in Scenario A.
Work needed, as AI does seem a little too dramatic, but might these visuals help our colleagues understand the temporary traffic lights? And yes, they are temporary in many cases, as fraud (and other integrity risks) are not uniform across project lifecycles, they crop up at different parts of the route. Helping people understand why, and what we’re protecting them from, might placate our less patient and cynical colleagues…
