Many companies have an anti-bribery policy, a gifts and hospitality register, sanctions screening, anti-money laundering checks and a code of conduct.
Then you ask about fraud.
Often, the answer becomes strangely vague. Fraud is treated as something finance might spot, internal audit might test, IT might prevent, or legal might deal with after the fact. Everyone recognises it as serious. Fewer people can explain how the company prevents it in the places where it is most likely to arise.
That gap matters for investors and operating partners because fraud is not a niche compliance topic. It is a practical operating risk.
In my conversation with Ross Butler on Fund Shack, we talked about why many businesses have frameworks for bribery, money laundering and human rights, but far less useful thinking about fraud. You can watch or listen to the full episode on Fund Shack.
Bribery is easier to label
Anti-bribery programmes have a clear story. They usually focus on improper payments, public officials, gifts, hospitality, agents, facilitation payments and conflicts of interest.
That clarity helps. It gives lawyers, compliance teams and boards a recognisable category. It also gives companies something to document.
Fraud is messier.
It can sit in sales forecasts, supplier invoices, payroll, expenses, inventory, project reporting, commissions, quality claims, customer refunds, procurement, cyber-enabled payment diversion, grant reporting, sustainability data or management accounts.
It can be committed against the company, by the company, or by people trying to help the company. It can involve employees, contractors, managers, suppliers, customers, agents or organised criminals outside the business.
That breadth is one reason companies under-manage it. When everything could be fraud, nobody knows where to start.
Fraud prevention is not just finance control
Finance controls matter, but they are not enough.
A payment control may catch a false invoice. It will not necessarily catch a sales team misrepresenting performance, a project manager hiding overruns, a distributor inflating end-customer demand, a local manager suppressing complaints, or a senior leader encouraging people to “make the number” without asking how.
Fraud often starts before the transaction. It starts with pressure, opportunity and rationalisation.
That means the framework needs to sit closer to the business decisions that create those conditions.
Make fraud specific to the operating model
A useful fraud framework starts with a simple question:
Where could someone deceive another person or system to gain an unfair advantage for themselves, for the company or for a third party?
Then apply that question to the business model.
For a services business, look at time recording, project margins, subcontractors, expenses, client claims and delivery reporting.
For a manufacturer, look at procurement, inventory, quality records, scrap, warranty claims, product substitution and distributor incentives.
For a regulated or healthcare business, look at eligibility, billing, patient or customer acquisition, referrals, clinical or technical records, and the gap between commercial pressure and professional judgement.
For an asset-heavy project business, look at contractors, change orders, milestones, local permits, community commitments, materials, delays and certification.
The point is not to create a fraud encyclopedia. It is to make the risk concrete enough that managers can see themselves in it.
Investors should ask for the fraud map
If a portfolio company says it has fraud covered, ask to see the map.
Not just the policy. The map.
- What are the top fraud scenarios for this business model?
- Which roles could create, approve, conceal or benefit from them?
- Which third parties could exploit the company or act on its behalf?
- Which controls would actually interrupt the scenario?
- Which indicators would show the board something is wrong?
- Who reviews exceptions, overrides and near misses?
- What has changed after incidents, complaints or audits?
If management cannot answer those questions, the framework may be more decorative than useful.
Keep it proportionate
Smaller and growth-stage companies do not need a giant fraud bureaucracy.
They do need a way to identify the few scenarios that would really hurt them, assign ownership, build simple controls into existing processes and learn when something goes wrong.
That might mean:
- tightening who can create or amend suppliers
- reviewing unusual discounts, credits or refunds
- checking distributor and introducer incentives
- testing payroll, expenses and procurement exceptions
- looking at project overruns, complaints and quality issues together
- making it easier for people to raise concerns early
- reporting fraud indicators to the board in plain language
This should feel like better management, not a compliance side quest.
The useful test
The best test is whether the fraud framework changes decisions.
Does it affect how the company designs approvals, chooses suppliers, sets targets, reviews exceptions, investigates concerns and learns from mistakes? Does it help managers spot pressure and rationalisation before they become incidents?
If the answer is no, the company probably does not have a fraud framework. It has a fraud policy.
For investors, that distinction matters. A policy may satisfy a checklist. A framework helps protect value.
Review note
- Gap filled: NW-014, a podcast-led article on fraud as an operating risk rather than a narrow legal or finance issue.
- Closest archive neighbours checked: Fraud Prevention Assessment; What the UK’s Failure to Prevent Fraud Offence Means for Portfolio Companies; Why don’t leaders want to save money?
- Why distinct: explains fraud as a practical operating category and portfolio oversight issue, rather than another failure-to-prevent article.
- Recommended video asset placement: full Fund Shack YouTube recording embedded at the top; replace with a fraud-specific short clip if one becomes available.
