Ethics Insight writing

Why do companies have anti-bribery policies but no useful fraud framework?

Fraud is often treated as either finance's problem or a legal category, when it should be managed as a practical operating risk across the business.

Many companies have an anti-bribery policy, a gifts and hospitality register, sanctions screening, anti-money laundering checks and a code of conduct.

Then you ask about fraud.

Often, the answer becomes strangely vague. Fraud is treated as something finance might spot, internal audit might test, IT might prevent, or legal might deal with after the fact. Everyone recognises it as serious. Fewer people can explain how the company prevents it in the places where it is most likely to arise.

That gap matters for investors and operating partners because fraud is not a niche compliance topic. It is a practical operating risk.

In my conversation with Ross Butler on Fund Shack, we talked about why many businesses have frameworks for bribery, money laundering and human rights, but far less useful thinking about fraud. You can watch or listen to the full episode on Fund Shack.

Bribery is easier to label

Anti-bribery programmes have a clear story. They usually focus on improper payments, public officials, gifts, hospitality, agents, facilitation payments and conflicts of interest.

That clarity helps. It gives lawyers, compliance teams and boards a recognisable category. It also gives companies something to document.

Fraud is messier.

It can sit in sales forecasts, supplier invoices, payroll, expenses, inventory, project reporting, commissions, quality claims, customer refunds, procurement, cyber-enabled payment diversion, grant reporting, sustainability data or management accounts.

It can be committed against the company, by the company, or by people trying to help the company. It can involve employees, contractors, managers, suppliers, customers, agents or organised criminals outside the business.

That breadth is one reason companies under-manage it. When everything could be fraud, nobody knows where to start.

Fraud prevention is not just finance control

Finance controls matter, but they are not enough.

A payment control may catch a false invoice. It will not necessarily catch a sales team misrepresenting performance, a project manager hiding overruns, a distributor inflating end-customer demand, a local manager suppressing complaints, or a senior leader encouraging people to “make the number” without asking how.

Fraud often starts before the transaction. It starts with pressure, opportunity and rationalisation.

That means the framework needs to sit closer to the business decisions that create those conditions.

Make fraud specific to the operating model

A useful fraud framework starts with a simple question:

Where could someone deceive another person or system to gain an unfair advantage for themselves, for the company or for a third party?

Then apply that question to the business model.

For a services business, look at time recording, project margins, subcontractors, expenses, client claims and delivery reporting.

For a manufacturer, look at procurement, inventory, quality records, scrap, warranty claims, product substitution and distributor incentives.

For a regulated or healthcare business, look at eligibility, billing, patient or customer acquisition, referrals, clinical or technical records, and the gap between commercial pressure and professional judgement.

For an asset-heavy project business, look at contractors, change orders, milestones, local permits, community commitments, materials, delays and certification.

The point is not to create a fraud encyclopedia. It is to make the risk concrete enough that managers can see themselves in it.

Investors should ask for the fraud map

If a portfolio company says it has fraud covered, ask to see the map.

Not just the policy. The map.

If management cannot answer those questions, the framework may be more decorative than useful.

Keep it proportionate

Smaller and growth-stage companies do not need a giant fraud bureaucracy.

They do need a way to identify the few scenarios that would really hurt them, assign ownership, build simple controls into existing processes and learn when something goes wrong.

That might mean:

This should feel like better management, not a compliance side quest.

The useful test

The best test is whether the fraud framework changes decisions.

Does it affect how the company designs approvals, chooses suppliers, sets targets, reviews exceptions, investigates concerns and learns from mistakes? Does it help managers spot pressure and rationalisation before they become incidents?

If the answer is no, the company probably does not have a fraud framework. It has a fraud policy.

For investors, that distinction matters. A policy may satisfy a checklist. A framework helps protect value.

Review note

More Ethics Insight writing