Deloitte - Review of Fraud Intelligence and Investigation Functions

‹ PrevPage 1 of 27 · Source p. 1Next ›

Deloitte.

National Disability Insurance Agency

Review of Fraud Intelligence and Investigation Functions

10 March 2022 Page 1 of 27

Deloitte Touche Tohmatsu FOI 22/23-0274 ABN 74 490 121 060

8 Brindabella Circuit Brindabella Business Park Canberra Airport Canberra, ACT, 2609 10 March 2022 Australia

Phone: +61 2 6263 7000 redacted: s22(1)(a)(ii) - irrelevant material www.deloitte.com.au

Chief Risk Officer National Disability Insurance Agency

Dear redacted: s22(1)(a)(ii) - irrelevant material

In accordance with Official Order N365006880, we have conducted a review of the National Disability Insurance Agency’s (NDIA or the Agency) Fraud Intelligence and Investigation Functions (the function).

We analysed and reviewed the Agency’s existing intelligence and investigations practices against contemporary industry leading practice and gathered insights on current pain points and opportunities for enhancement within the function.

Our review included discussions with internal Agency stakeholders, external stakeholders, review of documentation, benchmarking against our regulatory and industry leading best practice and engagement with our subject-matter experts.

Our report recognises and acknowledges that fraud mitigation is an enterprise-wide responsibility, implemented via the Agency’s three Lines of Defence model, with various Line 1 and Line 2 functions undertaking activities to prevent, respond and defend against fraud risk. This review acknowledges that the Agency has made significant investments to build and mature its capability to detect and respond to fraud since inception. More recently, this activity includes the ongoing work of the NDIA Fraud Taskforce, the recent implementation of the Compliance Response Team and Eligibility Integrity Uplift Project, as well as the ELT led Fraud Integrity Taskforce (FIT). These initiatives have helped drive prevention, detection and build capability to respond to fraud against the Scheme in a short period of time. In addition to these significant historical investments to uplift its fraud control capability, we also note that the Agency is balancing the reality of capacity limitations, capability uplift, organisational maturity and recent Covid19 restrictions. However, with the estimated growth in participant costs forecasted to increase to $59.3 Billion in 2029-30, and with the nature and intensity of opportunistic fraud and serious organised criminal activity targeting the Scheme becoming more pervasive, these historical measures are no longer sufficient.

This report provides targeted observations and recommendations for capability uplift across the Agency’s intelligence and investigations capabilities to prevent, detect and respond to fraud, and ensure they are fit for purpose for the scale of activity and growing risk profile of the NDIS. This will:

• Uplift processes, information, governance and technology to develop robust controls which can scale and evolve to the Agency’s changing requirements and operating environment. • Use of streamlined, semi-automated workflows to maximise process and resourcing efficiencies whilst employing an integrated approach that reinforces an Agency-wide culture of ownership & responsibility to mitigate fraud risk. • Bolster the use of available spectrum of treatment options to provide the Agency with a more holistic response to Fraud to help disrupt and deter opportunistic fraud and non-compliance.

The measures outlined in our recommendations will support the Agency to maximise return on investment to preserve the scheme integrity and support continued delivery of impactful services for people with disability across Australia.

We are pleased to provide you with our report. Should you have any questions or require additional information, please don’t hesitate to contact me on redacted: s22(1)(a)(ii) - irrelevant material.

Yours sincerely, redacted: s22(1)(a)(ii) - irrelevant material

Table of Contents

Executive Summary 5

A. Assessment Scope and Methodology 13 B. Observations and Recommendations 16 C. Implementation Road Map 28 D. Appendices 30 © 2022 Deloitte Touche Tohmatsu. NDIA | Fraud Intelligence and Investigation Functions Review 3

Glossary of Terms

Throughout this report, unless otherwise indicated, the following references apply. These references act to clarify the report and are not intended to be

authoritative.

ACFE

ACIC

ANAO

AFP

AUSTRAC

BAU

CMS

CRM

CRO

CRT

ELT

FIT

© 2022 Deloitte Touche Tohmatsu.

Association of Certified Fraud Examiners

Australian Criminal Intelligence Commission

Australian National Audit Office

Australian Federal Police

Australian Transaction Reports and Analysis Centre

Business as usual

Case management system

Customer relationship management

Chief Risk Officer

Compliance Response Team

Executive leadership team

Fraud and integrity taskforce

NDIA / the Agency

NDIS / the Scheme

Non-Compliance

Organised Criminals

Opportunistic Fraud

PRODA

Q&S Commission

RAB

Serious Organised Crime

SIB

Page 4 of 27

Definition

National Disability Insurance Agency

National Disability Insurance Scheme

An unintentional failure to abide by norms, laws or rules, usually by carelessness, accident or error.

Small, organised networks of entrepreneurial offenders, often transitory in nature, that develop to exploit particular opportunities for illegal profit

Use of a scheme or system for a wrongful purpose to dishonestly gain personal

benefits. This might involve misusing position or privileges, or dishonestly exploiting a vulnerability for personal gain.

Provider digital access

National Disability Insurance Scheme Quality and Safeguards Commission

Risk Advisory Branch

Criminal activity perpetrated by two or more offenders, that requires substantial planning and organisation, and involves sophisticated methods and techniques, typically committed in conjunction with other offences.

Scheme Integrity Branch

NDIA | Fraud Intelligence and Investigation Functions Review

Executive Summary

Page 5 of 2#

The Agency has made significant investments to build its capability to manage fraud, however an opportunity now presents to uplift this capability to address an increasing fraud risk profile commensurate with the expected growth of the Scheme.

Situation

The National Disability Insurance Scheme (NDIS or the Scheme) has been in operation since 2013, and includes 484,700 participants as at 30 September 2021. According to the Annual Financial Sustainability Report 2020/211, in 2029-30 it is estimated that the number of participants will increase to 859,328. These figures are significantly higher than originally envisaged by the Productivity Commission. With the forecasted increase in participants numbers, it is expected that total forecasted participant costs of $29.2 billion in 2021-22, will rise to $41.4 billion in 2024-25, and $59.3 billion in 2029-30 (on an accrual basis). Due to potential for exploitation, the NDIA’s fraud control arrangements are needed to ensure that the Scheme is protected from being misused and public confidence remains high.

Since inception, the Agency has made significant investments to build its capability to detect and respond to fraud: This includes the ongoing work of the NDIA Fraud Taskforce, the recent implementation of the Compliance Response Team and Eligibility Integrity Uplift Project, as well as the ELT led Fraud Integrity Taskforce (FIT). These initiatives have helped to drive fraud prevention, detection and response capability across the Agency, and serve to reinforce that fraud mitigation is an Agency-wide responsibility. In addition to these significant historical investments to uplift its fraud control capability, we also note that the Agency is balancing the reality of capacity limitations, capability uplift, organisational maturity and recent Covid19 restrictions.

Challenge

With the estimated growth of participant costs forecasted to increase to $59.3 Billion in 2029-30, the NDIS is increasingly exposed to the growing risk of highly sophisticated, complex serious and organised crime, criminal and opportunistic fraud perpetrated by Providers, Plan Managers, Partners in the Community, Participants, and unscrupulous family members. This has led the Executive Leadership Team (ELT) to question whether the Agency’s existing fraud intelligence and investigations functions have (1) the capability to mitigate and (2) the ability to scale to address the growing fraud risk within the Scheme. Deloitte was engaged in October 2021 to review the Agency’s existing fraud intelligence and investigations practices and benchmark current capabilities against contemporary industry leading practice (with consideration of current legislation and Commonwealth policies).

Our results

This report documents our observations on key procedural, process and system practices and risks for the Agency’s management of fraud against the Scheme:

• We assessed the potential exposures and gaps using the review methodology outlined in Figure 1 (Right). From our review and fieldwork, three overarching findings and nine observations related to these findings have been identified. • We have developed recommendations to address these observations and uplift current fraud control capability.

Figure 1: Review Methodology

redacted: s47G - business information

A. Assessment Scope and Methodology

Deloitte was asked by the National Disability Insurance Agency (NDIA) to undertake a review of the Agency’s Fraud Intelligence and Investigation Functions

Review Scope and Methodology

Background

Since inception in 2013, the NDIS has been primarily focussed on transitioning participants into the Scheme from state and territory funded support. As a result, participant growth was rapid, notably growing from 29,719 in 2016 to 466,619 by 30 June 2021, with payments also rising rapidly, from $4 billion in 2016-17 to more than $23 billion by 2020-21. This focus on participant transition has meant that there was insufficient attention on the commensurate growth of a robust control environment and associated systems expected of a scheme of this size and complexity today.

Not withstanding this limitation, the Agency has made significant steps to build and mature its capability to detect and respond to fraud since 2018. In July 2018, the Government established the NDIS Fraud Taskforce (the Taskforce), which aimed to reduce potential fraud within the Agency and strengthen the fraud prevention and detection capabilities. In addition to the Taskforce, the Agency has undertaken two-year program of work focusing on building capability and capacity across fraud prevention, detection, investigation/response, treatment of risks, monitoring and reporting.

However, with the growing risk of fraud and identified infiltration of serious and organised crime actors into the Scheme, as well as the forecasted participant costs increasing to $59.3 billion by 2029-30 (Annual Financial Sustainability Report 2020/21),1 puts into focus whether the Agency’s current approach to using intelligence and investigations to prevent, detect and respond to fraud is fit for purpose for the nature and scale of activity.

Scope

Deloitte was engaged to provide insights and recommendations for capability uplift across the Agency’s fraud intelligence and investigation functions, ensuring the Agency has the right resourcing, process, technology and data capabilities to effectively mitigate fraud perpetrated against the Scheme and assist with the Scheme’s long term sustainability.

In accordance with the signed Official Order dated 12 October 2021, we performed the following procedures:

• Reviewed the Agency’s existing fraud intelligence and investigations practices against contemporary industry leading practice (with consideration of enforcement options under current legislation). • Gathered high level insights on the indicative costs and benefits into any proposed capability uplift of the intelligence and investigations functions within the Agency, including through improved digital platforms. • Established appropriate lead and lag indicators for ongoing measurement of performance. • Gathered insights and ideas on the resourcing capability to meet the needs of the NDIS’s size, complexity and assist the Agency advance its capabilities.

Review Methodology

redacted: s47G - business information

B. Observations and Recommendations

C. Implementation Road Map

D. Appendices

Page 11 ofa

Appendix 1 – Recommendation Road Maps

Appendix 2 – Supporting Information

Appendix 2B

Forecasted Tip Off Volume Calculations

Tip-Off Average Calculations

Period FY Total Tip Offs Average Increase % Source
Q1 2019/20 957 N/A November 2020 – CRO Update
Q2 2019/20 1053 10% November 2020 – CRO Update
Q3 2019/20 1301 24% November 2020 – CRO Update
Q4 2019/20 1766 36% November 2020 – CRO Update
Q1 2020/21 2140 21% November 2020 – CRO Update
Q2 2020/21 2177 2% February 2021 – CRO Update
Q3 2020/21 1907 -12% May 2021 – CRO Update
Q4 2020/21 2435 28% August 2021 – CRO Update
Average Increase per Quarter 15%

Forecasted Tip-Off Volume Calculations

Period FY Total Tip Offs Average Increase % Source
Q1 2021/22 2800 15% Forecast – 15% compounded increase per quarter
Q2 2021/22 3220 15% Forecast – 15% compounded increase per quarter
Q3 2021/22 3703 15% Forecast – 15% compounded increase per quarter
Q4 2021/22 4259 15% Forecast – 15% compounded increase per quarter

Appendix 3 – Benchmarking

Appendix 4 – Lead and Lag Indicators

Appendix 5 – References

References

Throughout this report, the following references have been applied to support our observations and recommendation. These references act to clarify the report and are not intended to be authoritative.

Reference Number Reference
1 National Disability Insurance Agency, 2021, Annual Financial Sustainability Report 2020-21 https://www.ndis.gov.au/media/3579/download?attachment.
2 Organised Criminals are defined as small, organised networks of entrepreneurial offenders, often transitory in nature, that develop to exploit particular opportunities for illegal profit (Eck & Clarke, 2013, Centre for Problem-Oriented Policing, USA).
3 Australian Government Department of Finance, n.d., Risk Appetite and Tolerance https://www.finance.gov.au/government/comcover/education/risk-appetite-and-tolerance .
4 Australian Criminal Intelligence Commission, 2017, Australian Criminal Intelligence Management Strategy 2017-2020, https://www.afp.gov.au/sites/default/files/PDF/ACIM-strategy-2017-20.pdf.
5 Australian Criminal Intelligence Commission, 2018, 2017-18 Annual Report https://www.acic.gov.au/sites/default/files/2020-08/acic_2017-18_ar_digital.pdf, page 243.
6 Australian National Audit Office, 2018, Better Practice Guide: Administering Regulation https://www.anao.gov.au/work/audit-insights/administering-regulation.
7 Australian National Audit Office, 2019, National Disability Insurance Scheme Fraud Control Program https://www.anao.gov.au/work/performance-audit/national-disability-insurance-scheme-fraud-control-program.
8 Association of Certified Fraud Examiners, n.d., Using Data Analytics to Detect Fraud https://www.acfe.com/topic.aspx?id=4294970985.
9 Australian National Audit Office, 2010, Community Intelligence – Collecting and Processing Tip-offs https://www.anao.gov.au/work/performance-audit/community-intelligence-collecting-and-processing-tip-offs.
10 Association of Certified Fraud Examiners, 2019, In-House Fraud Investigations Teams: 2019 Benchmarking Report https://www.acfe.com/benchmarking-report-2019.aspx.
11 Australian Transaction Reporting and Analysis Centre, n.d., Regulatory Quick Guide – Governance: board and senior management oversight https://www.austrac.gov.au/sites/default/files/2021-03/AUSTRAC_REQuickGuides_Governance_MAR23.pdf.
12 Australian Government Attorney General’s Department, 2017, Commonwealth Fraud Control Framework https://www.ag.gov.au/integrity/publications/commonwealth-fraud-control-framework.
13 Australian Government Attorney General’s Department, 2011, Australian Government Investigations Standards 2011 https://www.ag.gov.au/sites/default/files/2020-03/AGIS%202011.pdf.
14 Australian Government Attorney General’s Department, 2016, National Identity Proofing Guidelines https://www.homeaffairs.gov.au/criminal-justice/files/national-identity-proofing-guidelines.pdf.
15 Standards Australia, 2021, AS 8001:2021 Fraud and corruption control https://store.standards.org.au/product?designationId=AS%208001%3A2021.

References

Throughout this report, the following references have been applied to support our observations and recommendation. These references act to clarify the report and are not intended to be authoritative.

Reference Number Reference
16 International Standards Organisation, 2018, ISO 31000:2018 Risk Management https://www.iso.org/standard/65694.html.
17 Commonwealth Director of Public Prosecutions, 2021, Prosecution Policy of the Commonwealth https://www.cdpp.gov.au/sites/default/files/Prosecution%20Policy%20of%20the%20Commonwealth%20as%20updated%2019%20July%202021.pdf.
18 Commonwealth Director of Public Prosecutions, 2020, Guidelines for dealings between Investigators and the Commonwealth Director of Public Prosecutions https://www.cdpp.gov.au/sites/default/files/Guidelines%20for%20dealings%20between%20Investigators%20and%20the%20CDPP%20-%20%20September%202021.pdf.
19 Australian Federal Police, 2020, Case Categorisation & Prioritisation Model https://www.afp.gov.au/sites/default/files/PDF/ccpm-dec-2020.pdf.
20 Australian Federal Police, n.d., Search warrants – guidelines https://www.afp.gov.au/what-we-do/operational-support/search-warrants-guidelines.
21 Australian Federal Police, n.d., Search warrants – procedures https://www.afp.gov.au/what-we-do/operational-support/search-warrants-procedures.
22 Association of Certified Fraud Examiners, 2020, Anti-Fraud Playbook https://www.acfe.com/uploadedFiles/ACFE_Website/Content/fraudrisktools/Antifraud-Playbook.pdf.
23 Australian Taxation Office, n.d., ATO Fraud and Corruption Control Plan 2020-21 https://www.ato.gov.au/General/The-fight-against-tax-crime/In-detail/ATO-Fraud-and-Corruption-Control-Plan-2020-21/#Fraudandcorruptionprevention.
24 Australian Government Commonwealth Fraud Prevention Centre, n.d., Investigate fraud https://www.counterfraud.gov.au/fraud-countermeasures/investigate-fraud.
25 City of London Police, National Lead Force Performance Outcomes, 2013 https://democracy.cityoflondon.gov.uk/documents/s17064/Pol_07-13_KPI%20Framework%20-%203rd%20Quarter%20v%203.pdf.
26 The Institute of Internal Auditors Australia, 2018, Fraud Risk Indicators White Paper https://iia.org.au/sf_docs/default-source/technical-resources/2018-whitepapers/iia-whitepaper_fraud-risk-indicators.pdf?sfvrsn=2.
27 Australian Government Department of Prime Minister and Cabinet, n.d., Regulator Performance Guide https://deregulation.pmc.gov.au/priorities/regulator-best-practice-and-performance/regulator-performance-guide.
28 Australian Government Attorney General’s Department, Protective Security Policy Framework: Paper 11 Robust ICT Systems https://www.protectivesecurity.gov.au/system/files/2021-06/pspf-policy-11-robust-ict-systems.pdf

Appendix 6 – Stakeholder List

Stakeholder Listing

As part of this review, we undertook a number of interviews with the following stakeholders.

Name Function Date Interviewed
redacted: s22(1)(a)(ii) - irrelevant material Branch Manager, Scheme Integrity Branch 7 October 2021, 11 November 2021
Director, Investigations 10 November 2021, 11 November 2021
Director, Intelligence 28 October 2021, 8 November 2021, 11 November 2021
Director, Compliance 1 November 2021
Deputy Chief Legal Counsel, Legal 12 November 2021
Director, Strategy and Design 3 November 2021
Branch Manager, Risk Advisory 8 November 2021
Director, Proactive Compliance 4 November 2021, 7 December 2021
Director, Data analytics 28 October 2021
General Manager, Operations & Support 27 October 2021
Chair, Risk Committee 21 October 2021
Australian Federal Police 3 November 2021
A/g Registrar, Quality and Safeguards Commission 2 November 2021
A/g Deputy Registrar, Quality and Safeguards Commission 2 November 2021
A/g Chief Investigator, Quality and Safeguards Commission 2 November 2021
Director National Compliance, Quality and Safeguards Commission 2 November 2021
Scheme Actuary, NDIA 30 November 2021

Appendix 7 – Documents Reviewed

Document Listing

As part of this review, we reviewed the listed documents below that were provided by the Agency.

Document

01

02

03

04

05

06

07

08

09

10

11

12

13

14

15

16

17

18

19

20

Document Name

Intelligence and Investigations Review - September 2021

NDIA Fraud and Corruption Control Plan - August 2020

Staff Information Guide final Jan 2020

Compliance and Enforcement Framework - March 2020 November 2020 - Risk Co - CRO Update

November 2020 - Risk Co - Att A - Q1 CRO Detailed Report -FINAL November 2020 - Risk Co - Att B - Scheme Integrity Control Principles February 2021 - Risk Co - CRO Update - final

February 2021 - CRO Update Q2 2020-21 - final

May 2021 - Risk Co - CRO update - FINAL

May 2021 - Risk Co - Attachment A - Q3 CRO Report Final

August 2021 - Risk Co - CRO Update - FINAL

August 2021 - Risk Co - Fraud and compliance update - FINAL August 2021 - Risk Co - Att B - CRO Q4 Update - Dashboard - FINAL

NDIA Fraud Strategy

NDIA Corporate Plan 2021-25

NDIA Org Chart

Audit Committee Agenda June 2020 - September 2021

Risk Committee Agenda June 2020 - August 2021

Guideline on Exhibit Management

© 2022 Deloitte Touche Tohmatsu.

Document

21

22

23

24

25

26

27

28

29

30

31

32

33

34

35

36

37

38

39

40

Document Name

NDIA Investigation Handbook

Case Closure and Summary Report Part | and Part II

CLAPOOM Request Letter Template

Evaluation Report

Example NDIS Investigation Plan

Example Short Form Investigation Plan

Intelligence and Investigation Prioritisation Model Form

Investigation Plan SOP

Investigation Review SOP

Long Form Investigation Plan - Long Form

NDIA Fraud and Corruption Control Plan August 2020

NDIS Investigation Plan Instructional Template

Post Evaluation Investigation Internal Referral Form

ROI Invitation Letter Template

Scheme Integrity Risk and Control Report

Short Form Investigation Plan Instructional Template

Short Form Investigation Plan

Strategic Briefing Template

Vulnerable Witness SOP

Witness Information Sheet - Part.1 (First Contact)

age 23 0

Document

41

42

43

44

45

46

47

48

49

50

51

52

53

54

55

56

57

58

59

60

Document Name

Witness Information Sheet - Part 2 (Post Statement)

Scheme Integrity - Overview

Risk and referral criteria

NDIA Fraud Risk Profile Development Framework v1.0

PID

Board Paper on Identity Management

Identity Management Framework - Appendix A to Board paper

Scheme Integrity - Current State

Fraud Taskforce Risk Register (as at 14-10-2021)

Compliance Response Summary - Light Touch Policy - final - Nov 19 (1) High Value Plan Assessment - final - Nov 19

NDIA Executive Report Oct v.09

Participant - Provider Relationship Pilot - final - Nov 19

PLAN MANAGERS - final - Nov 19

Assessment Standard Operating Procedure V2.1

Intake Standard Operating Procedure (SOP) V1.1

Quality Plan Compliance Section (draft) v0.5

Standard Operating Procedure - Desk Based Compliance Review V2.1

Endorsed

2.4 Compliance Response Taskforce

2.4.a CRT Execution Plan

NDIA | Fraud Intelligence and Investigation Functions Review 71

Document Listing

As part of this review, we reviewed the listed documents below that were provided by the Agency.

Document

61

62

63

64

65

66

67

68

69

70

71

72

73

74

75

76

77

78

79

80

Document Name

2.4.b Behavioural Change Model - concept slide

2.4.b Behavioural Change Model - concept slide

2.4.c Provider Self Assessment Letter and Declaration

11 October 2021 - Compliance Response Taskforce - FINAL

4 August 2021 - Compliance Response Taskforce update

19 August 2021 - 5.4.B - Compliance Response Taskforce progress update

  • FINAL 20 July 2021 Attachment B - Compliance Response Taskforce update

FINAL

2.2 Annual Strategic Risk Review FY2021-22 - FINAL

2.2a FY2021-22 Strategic Risk Performance Metrics & Tolerances - FINAL

October - Chief Risk Officer update

September - CRO Update

RC Item 3.1 Quarter 3 Strategic Risk Performance Report

RC Item 3.1a NDIA Strategic Risks Performance Report

Risk Co Agenda Item 4.3 - Scheme Integrity Update (June 2020)

Risk Co. Agenda Item 3.2a Mapping against legislative obligations

Item 2.2 - Attachment A - final

Risk Co Agenda Item 2.2 - Strategic Risk Review FY21-22 - final

Draft Risk Co OOS paper - Attachment A

Draft Risk Co OOS paper - PSPF maturity self-assessment - covering paper

Risk Co. Agenda Item 3.2 Risk Management Strategy Annual Review

© 2022 Deloitte Touche Tohmatsu.

Document

81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99

100

Document Name

Agenda - CMC - 21 July 2021_Redacted

CMC Meeting Minutes 21 July 2021.docx_Redacted

CMC Summary of Decisions Register 21 July 2021_Redacted

Endorsed Minutes 11-10-2019

Joint Operational management Committee Minutes 02 12 19

Joint Operational Management Committee Minutes 29 Jan 2020

Joint Operational Management Committee Minutes 7 October 2020_

NDIA CMC - Terms of Reference V0.6

SIGNED Joint Operational Management Committee Minutes 02 12 19

SIGNED Joint Operational Management Committee Minutes 06 11 2019

Terms of Reference JOMC-I - Final

Agency Risk Appetite Statement (RAS)

Agency Risk Management Strategy

Risk Committee Charter

FC road map Closure Report v0.1

NDIA Fraud and Compliance road map - 2 Year Program of Work v1.0

NDIS Fraud Horizon Map v.12 20200217

Identity Management Framework - Appendix A - FINAL

Business Plan 20-21 Plan

RIP 2020-21

Page 24 of 27

Document

101

102

103

104

105

106

107

108

109

110

112

113

114

115

116

117

118

119

120

Document Name

Scheme Integrity Business Plan v2.2

SI RIP and Business Plan 21-22

NDIA Fraud Risk Register 31 October 2020

NDIA Fraud Risk Register 6DEC 2019

NDIA Fraud Risk Register March 2021

Fraud Intelligence Team 2020-2021 Summary

Visio-Fraud Intelligence Team Report 30 June 2020

ABR Tool V1.1

Altia 6.2.0 V3 SOP

Alita Investigation Toolbar Guide

AUSTRAC Search Request Template

Bank Letter - Request for information Part VIID Crimes Act

Bank Requests V1.1

Call Recordings V1.0

Case Management System - Fraud Intelligence Process V1.1

Version 03_19

CMS Intelligence Workflow

Commission Referral Template

Compliance Lock SOP

Compliance Lock System Process

NDIA | Fraud Intelligence and Investigation Functions Review 72

Document Listing

As part of this review, we reviewed the listed documents below that were provided by the Agency.

Document

121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139

140

Document Name

Criminal History Authorisation Form - Initial Request

Criminal History Checks v1.0

Equifax V1.0

Final Template - s66(1)(a) PIC - Disclosure of Information Cth Department for its investigation

Final Template - s66(1)(a) PIC - Disclosure of Information - NDIA TF Operation-re Parties of Int.

Final Template - s66(1)(a) PIC - Disclosure of Information - Request for infor by law enforcement-non-TF

Finalisation checklist V1.0

Financial Analysis Template SOP VO.1

Financial transaction analysis SOP 0.4

Fraud Intel New Starter Checklist

Fraud Intel Process Map V2.0

Fraud Intelligence Team Employee Exit Checklist V1.0

Fraud Methodology Report V1.0

Guide to myGov V1.0

Guide to PSCD V1.1

iBase Bulk Import Spec

Information Release Template V1.0

Intelligence & Investigation Prioritisation Model V1.0

Intelligence Briefing Template

Intelligence framework on a page

© 2022 Deloitte Touche Tohmatsu.

Document

141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159

160

Document Name

Intelligence Functional scope V1.0

Intelligence Staff Guidelines V1.0

Intelligence Style Guide V1.0 FINAL

Medicare Information Request Letter V2

MyGovID Connection Approval Form

NDIA Fraud Risk Register 31 October 2020

NDIA Intelligence Sources

OGA Systems Access Form v4.2 2019

Open Source Intelligence Guidelines V1.0

Passport Requests V1.0

Payment Request Process

Payment Suspension Letter V3.0

Person Profile

PRODA V1.2

PSCD Access and Installation

Request for disclosure of passports information V1.0

Risk and Prioritisation Review Template V1.2

Section 55 Template - bank requests V1.1

SOM - Application of Compliance and PRODA Locks v1.1

SOP - Australian Tax Office Information

Page 25 of 27

Document

161

162

163

164

165

166

167

168

169

170

171

172

173

174

175

176

177

178

179

180

Document Name

SOP - Universal Student Identifiers

SOP Assessment Finalisations V1.0

SOP AUSTRAC Information Requests v2.0

SOP Quality Assurance v1.0

Tactical Intelligence Report 2.1

Template RFI to NDIA (Sept 2019)

USI - Request for information

4.2 Attachment A - DRAFT PSPF 2019-20 Assessment - National Disability

Insurance Agency

4.2 Attachment B - Security Advisory Committee Terms of Reference ELT approved June 2020

Item 4.3 - Strategic Risk Performance Metrics

Item 4.4 Incident Regulatory Escalation Criteria Refresh

Risk Co. Agenda Item 4.2 - PSPF Maturity Self Assessment

Overview of FIT initiatives - FINAL

Reporting Overview

Detection Profile Register vO.7

NDIA 60DayCollectionofGoods

NDIA Return to Owner receipt

NDIS 3KElectronicPropertyMovementRecord

NDIS ElectronicPropertySeizureRecord

NDIA | Fraud Intelligence and Investigation Functions Review 73

Document Listing

As part of this review, we reviewed the listed documents below that were provided by the Agency.

Document

181

182

183

184

185

186

187

188

189

190

191

192

193

194

195

196

197

198

199

200

Document Name

PROP - 01 - Chain of Custody

PROP - 02 - Property Seizure Records

PROP - 03 - Return to Owner

PROP - 04 - Security Incident - Property

PROP - 05 - Request for Disposal

PROP - 06 - Secure Transfer ver 1.0

Disclosure Certificate

Witness Contact List MASTER

Witness Contact List SHORT (open for instructions)

How To - Disclosure Index Linking FEB21

How To - Evidence Index Linking FEB21

CMS Intelligence Workflow

Critical Decision Guidelines

Intelligence Staff Guidelines

Intelligence Style Guide

NDIA CMC - Terms of Reference

Open Source Intelligence Guidelines

Restricted Inquiry

Taskforce Investigation - Roles and Responsibilities

Working with Children and Vulnerable People Policy

© 2022 Deloitte Touche Tohmatsu.

Document

201 202 203 204 205 206 207 208 209

210

213 214 215 216 217 218 219

220

Document Name

Our TIS Client Code

Pre Booked Onsite appointments (TIS Online)

Pre Booked Phone Appointments

On Demand Phone

A guide to TIS Online

SOP Preferred Method Communication

SOP TIS Call flow guide

AGS Advice - Scope and uses of NDIA’s fraud investigation

NDIA question on witnessing statements in matters to be prosecuted in the Victorian jurisdiction 3LA-AffOrdertoprovideinformationorassistance 3LA-AppOrdertoprovideinformationorassistance 3LA-Ordertoprovideinformationorassistance

AFP Letter Hearing of application for 3LA

Information provided 3LAOrder or consent

Multiple Person and Premises Affidavit

Multiple Premises Affidavit

Open Notebook

Person Affidavit

Person Warrant

Page 26 of 27

Document

221

222

223

224

225

226

227

228

229

230

231

232

Document Name

Premise Affidavit

Premise Warrant

Process for notifying Hearing application 3LA

Rights Occupier English

Rights Person Searched

SW Long Guide

SW Roles Responsibilities

SW Short Guide

Project Ivory Fraud Methodology Report

Intelligence Team — Services Australia Data Exchange Information

Intelligence Team — ACIC Data Exchange Information

Intelligence Team — Department of Health Data Exchange Information

NDIA | Fraud Intelligence and Investigation Functions Review 74

Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms, and their related entities (collectively, the “Deloitte organisation”). DTTL (also referred to as “Deloitte Global”) and each of its member firms and related entities are legally separate and independent entities, which cannot obligate or bind each other in respect of third parties. DTTL and each DTTL member firm and related entity is liable only for its own acts and omissions, and not those of each other. DTTL does not provide services to clients. Please see www.deloitte.com/about to learn more.

Deloitte is a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories (collectively, the “Deloitte organisation” serves four out of five Fortune Global 500® companies. Learn how Deloitte’s approximately 312,000 people make an impact that matters at www.deloitte.com.

Deloitte Asia Pacific

Deloitte Asia Pacific Limited is a company limited by guarantee and a member firm of DTTL. Members of Deloitte Asia Pacific Limited and their related entities, each of which are separate and independent legal entities, provide services from more than 100 cities across the region, including Auckland, Bangkok, Beijing, Hanoi, Hong Kong, Jakarta, Kuala Lumpur, Manila, Melbourne, Osaka, Seoul, Shanghai, Singapore, Sydney, Taipei and Tokyo.

Deloitte Australia

The Australian partnership of Deloitte Touche Tohmatsu is a member of Deloitte Asia Pacific Limited and the Deloitte organisation. As one of Australia’s leading professional services firms, Deloitte Touche Tohmatsu and its affiliates provide audit, tax, consulting, risk advisory, and financial advisory services through approximately 8000 people across the country. Focused on the creation of value and growth, and known as an employer of choice for innovative human resources programs, we are dedicated to helping our clients and our people excel. For more information, please visit our web site at https://www2.deloitte.com/au/en.html.

Liability limited by a scheme approved under Professional Standards Legislation. Member of Deloitte Asia Pacific Limited and the Deloitte organisation.

© 2022 Deloitte Touche Tohmatsu

Page 27 of 27