No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

Bolstering Compliance as Global COVID Fraud Enforcement Takes Shape

5 Ways to Measure and Mitigate Fraud Risk

by Toby Duthie, Matt Bedan and William Mui
July 16, 2020
in Featured, Fraud
Gavel Law Hammer with Coronavirus Covid-19 3D image

Governments worldwide are beginning to crack down on abuse of programs meant to protect businesses amid the COVID crisis. Forensic Risk Alliance’s Toby Duthie, Matt Bedan and William Mui offer five practical tips to aid organizations in managing this growing risk.

In response to COVID-19, governments across the globe have enacted substantial public sector stimulus programs to protect struggling businesses and employees. As countries begin to take steps to reopen to a post-COVID world, businesses are facing a new set of challenges: Enforcement agencies are preparing to aggressively crack down on abuse of those programs.

Most recently, furlough fraud has been top of mind in that respect, as new allegations in Europe point to extensive misappropriation within government furlough support programs. Recent studies in the U.K. and France indicate that as many as one in three furloughed employees have been asked to work during their furlough periods. As domestic agencies prepare to investigate, solicitors have anecdotally reported an “avalanche” of complaints that are likely to foretell significant public and private whistleblower activity.

Furlough fraud is just one example. In the coming months, the enforcement lens will widen significantly beyond furlough fraud and shift to larger businesses that received government bailouts. Although many of these direct-to-industry loan schemes have longer tails and have not yet made headlines with regard to fraud, they are no less risky for the organizations involved. Experience tells us that over time, these larger organizations will make for increasingly politically attractive and compelling targets, particularly if the perception arises that public stimulus funds were directed toward any use other than the preservation of rank-and-file jobs. For larger organizations, it will be critical to establish an unimpeachable “forensic” audit trail that demonstrates that all stimulus funds were used in accordance with their respective program’s obligations.

Given the changing landscape – economic, commercial and regulatory – this may not be as easy as it seems. In light of this, we offer five practical suggestions to help businesses measure and mitigate this risk exposure. It is worth considering how governments will enforce and how easy (or not) it will be for them to make their case. A lack of affirmative evidence can be very damaging, as companies will struggle to prove that any issues or clear abuse is not anomalous but systemic.

1. Understand Obligations and Prioritize Compliance

Organizations must carefully review eligibility requirements (which will likely evolve over time), certifications and use restrictions associated with every government loan or grant. Each program should have a carefully thought-out and documented end-to-end process, which includes checklists for regulatory/contractual obligations and maker/checker controls for payments utilizing government funds. As the obligations are determined, each should be translated into corresponding policies, standard operating procedures and trainings in order to facilitate compliance and prevent potential violations.

For example, companies should take proactive measures to ensure that furloughed employees are not asked or pressured to work and create and then maintain contemporaneous evidence to this effect. This includes promoting transparency around who is furloughed and when and what the protocols are for furloughed workers. Companies might additionally consider preventative IT controls, such as restricting network access to employees during their furlough periods.

HR training should be provided to managers and workers on their individual responsibilities to maintain compliance, and compliance teams should be thoroughly trained on the underlying obligations and corresponding rules to monitor compliance. They should understand:

  • What constitutes an issue?
  • What is a false positive?
  • And finally, how can this information be cycled back into the compliance process to make it not only more efficient, but more importantly, more accurate and effective at managing and mitigating risk?

Larger businesses that have taken part in direct treasury loan schemes will have more comprehensive and longer-term obligations to account for. This will likely include establishing payroll and disbursement controls to ensure that loan requirements regarding, for example, executive pay or stock buy-back plans are adhered to.

2. Harness and Organize Data and IT Systems

The U.S. Department of Justice’s (DOJ) recent update to its “Evaluation of Corporate Compliance Programs” guidance makes it clear that organizations are expected to leverage data, metrics and other objective evidence to test that their compliance program is working effectively. Particularly for larger multinational companies, this process should go beyond simply tracking traditional compliance data (such as training and audit metrics) and encompass all of the various sources of operational data that could potentially be put to use.

For some companies, this may mean setting up additional general ledger accounts or cost centers to track and account for every cent tied to government stimulus requirements. Financial tracking in this manner should demonstrate a clear correlation between regulatory/contractual obligations and the sources of data that could potentially indicate compliance, or noncompliance, for each.

3. Utilize Data Analytics

By utilizing advances in data analytics, organizations can enhance conduct detection and replace and/or enhance extensive manual controls and verification activities. To do this effectively, businesses must leverage the data of all relevant sources, including sales and product data, performance-management data and customer/patient records. An inclusive data analytics model can give a view of risk across activities, business units and geographies. Companies should also consider creating specific sets of compliance reports built directly around government claims or government compliance and embedding them directly into their executive reporting portfolio.

Finally, companies should approach data sources (particularly outside sources) critically and perform the due diligence necessary to understand where the data comes from and how it was created. This includes validating using “golden source” data sets and exercising audit rights for vendors that could potentially impact compliance with relevant programs. This work could have added benefits to a company’s wider compliance program; the better a company knows its data, the more effectively it can be leveraged in adjacent internal monitoring, investigations and compliance analysis.

4. Bolster Internal Whistleblower Programs

An effective internal reporting mechanism is not only a key part of the DOJ’s Guidance, but also an essential element of a strong compliance culture. Studies have shown that strong internal whistleblower programs help foster an atmosphere of trust and open communication, which in turn increases the odds that an employee with a compliance concern will report internally, instead of through the government. Ultimately, companies with higher usage of whistleblower programs have statistically fewer lawsuits and enforcement actions. Thus, it is critical that organizations take internal whistleblower reports very seriously and remediate accordingly.

Implement or maintain a system and create management information to ensure that these complaints are followed up on and closed out as appropriate.

5. Monitor, Audit and Remediate Comprehensively

Companies should adopt stringent compliance and risk management oversight, focusing particularly on data monitoring and documentation, and maintain a clear and comprehensive audit trail in accounting and enterprise resource planning (ERP) systems. This includes documenting all system reviews, upgrades or enhancements undertaken in response to new government obligations.

For example, companies with furlough fraud risk should utilize data within the ERP and IT systems to monitor and review timesheets, expenses, email traffic and usage of firm assets such as computers, messaging and phones to detect anomalies. Once the necessary tracking and rules are implemented, the associated reporting should be systematic, transparent and insightful. In short, if monitoring mechanisms do not give clear insight into possible issues and escalate red flags to the appropriate stakeholders, then they are not adequately serving their intended purpose.


Tags: COVID-19Data AnalyticsWhistleblowing
Previous Post

The Psychology of Phishing Victims and How to Overcome it

Next Post

As CCPA Enters Enforcement, the Cost of Email Mistakes Becomes Clear

Toby Duthie, Matt Bedan and William Mui

Toby Duthie, Matt Bedan and William Mui

Toby Duthie is a Founding Partner of Forensic Risk Alliance (FRA) and head of its U.K. and European offices. He has more than 20 years of experience in financial analysis, complex financial modeling, investigations and compliance reviews. Toby has worked on many complex financial frauds and bribery investigations, most notably leading the FRA team supporting Airbus in a multiyear, multinational investigation, resulting in a €3.6 billion settlement with four investigative authorities across France, the U.K. and the U.S.
Matt Bedan is an Associate Director in FRA’s Washington, D.C. office. He is a licensed attorney with over 11 years of public and private sector experience with complex investigations, regulatory compliance and anti-corruption matters. Matt specializes in the investigation, detection and prevention of potential statutory and regulatory violations. He also assists clients with anti-corruption and regulatory compliance reviews and assessment of internal controls.
William Mui is a data analytics and forensic services professional in FRA’s New York office, with extensive experience in designing and delivering end-to-end forensic analytics solutions. These include data management, data analytics and sciences and advanced analytics and modeling for investigative, dispute and compliance matters. He has over 12 years of experience leading cross-functional teams of compliance and technology professionals across a broad spectrum of industries.

Related Posts

check engine light

What Gets Measured Gets Managed, but What Actually Matters in Compliance?

by Keshonda Walker
May 16, 2025

Looking beyond standard measurements to identify the quiet signals that help compliance teams address issues before they become crises

hidden value abstract

CCO Insights: How to Articulate the True Value of Your Compliance Program

by Kenneth Koch and Phillip Ostwalt
May 14, 2025

Benefits of robust programs aren’t always obvious, but buy-in remains critical

doj sign and sculpture

DOJ’s New CEP Proposes Guaranteed Declination for Some Self-Reporters

by Jennifer L. Gaskin
May 13, 2025

The Trump Administration continues reshaping its approach to corporate crime, with the DOJ issuing major revisions of its corporate enforcement...

new yorkers in covid masks on street

Covid Fraud Enforcement (Yes, This Is Still a Thing)

by Denise M. Barnes and Brian Irving
February 7, 2025

With $2B recovered and $36B in estimated fraud, DOJ signals years of continued pandemic relief investigations ahead

Next Post
woman at laptop writing emails

As CCPA Enters Enforcement, the Cost of Email Mistakes Becomes Clear

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights