Earlier this year, I asked why most firms (growth-stage and beyond) have bribery, corruption, and sometimes money laundering frameworks, but none for other types of fraud we know to be more common (see chart from the ACCA combatting fraud survey below).
A former colleague, and head of compliance at a large multinational, sent a direct message saying, “because unlike money-laundering, sanctions breaches or corruption, there are no laws explicitly prohibiting the occurrence of fraud and sanctioning those businesses that allow it to happen.”
Yeah, but no but
Picking on the UK, the Bribery Act came into force nearly 15 years ago. Since then, we’ve had ~6 prosecutions and a couple of deferred prosecution agreements. Being generous, let’s round that up to 10 prosecutions. Some of those 10 were fairly modest Ltd companies. There are 2.1 million actively trading Ltd companies, and about 40,000 turn over £5m or more.
10/15(yrs) = 0.7 prosecutions per annum.
0.7/40,000 = 0.0000175
Or… 0.00175%
Yes, there are other, more aggressively prosecuted pieces of legislation, but you get the point.
And, I’m picking on bribery because most of those prosecutions were illegal payments to get “undue benefit” (i.e., to win).
The math doesn’t math
So, what I’m being told is that a business leader sees the cost benefit in investing in an anti-bribery system where the upside is potentially winning and the downside of getting caught and prosecuted is a fraction of a percent…?
I’m not saying that is the calculation, and I am deliberately suggesting nefariousness, but, to make a point.
The cost of fraud, at the median point, for a business with <100 people is now $126,000 (greater than the median loss for 10,000+ organisations). The average loss per case in the same ACFE study was just under $1.5m.
So, business leaders see ROI in preventing bribery, even when prosecution is remote, but no point in preventing fraud when an average mid-cap might lose money with the following probability:
- According to the BDO Fraud Survey (which tracks UK companies with 200+ employees), 42% of mid-sized businesses fell victim to fraud in 2024. This was a decrease from 60% in 2023 and a peak of over 68% in 2022 during the height of the cost-of-living crisis.
- The 24-Month Trend: PwC’s UK Economic Crime Survey found that 64% of UK businesses experienced some form of fraud, corruption, or economic crime within any given two-year window.
- The Size Vulnerability: The UK Government’s Economic Crime Survey notes that while the baseline annual fraud rate across all UK businesses is 27%, the rate jumps dramatically for medium and large corporations. Their larger supply chains, higher transaction volumes, and decentralised workforces create far more targets.
What’s your problem?
So, the problem isn’t probability. Bribery (or money laundering) prosecutions can’t be driving the behaviour, at least not rationally, or alone.
I think it’s because we do a terrible job of articulating and explaining fraud. What it is, where it occurs, why, how, and when. We then do an equally poor job of building fraud prevention measures that don’t drive everyone nuts.
In this context, fraud prevention has to move in the direction of cybersecurity - security-by-design. Building the prevention, detection, and response capabilities into existing processes. I can’t address that in its entirety in a post, but I will direct you to the three tools below that we drafted for the Fraud Advisory Panel, and its sister organisation, the Business Fraud Alliance.
Maybe in a future edition I might run a Fraud Prevention AI 101, showing how these PDFs could be turned into prompt packs to integrate into existing processes (e.g., reconciliations, vendor master data, inventory management, accounting, etc.). Would that be useful?
For now, find your sector, have a read, and let me know what you think.
