Fraud and Risk Management
National Office
s22(1)(a)(ii) - irrelevant material August 2014
Page 198 of 292
Session Outline
-
What is Risk/Risk Management?
-
Why is it important?
-
The Agency’s approach to Risk Management
-
What is your role?
-
Fraud in the Commonwealth
-
The Agency’s approach to Fraud Control
-
What is your role?
What is Risk?
“Risk is the effect of uncertainty on objectives”
AS/NZS ISO31000:2009
Page 200 of 292
Risk Management
Risk Management is the process of identifying, analysing and evaluating risks with a view to ensuring the effective management of potential opportunities while reducing or avoiding adverse effects.
Page 201 of 292
Why is it important?
- To minimise the negative impact of risks upon achievement of objectives; and
- To maximise the Agency’s ability to realise potential opportunities
Prevention is better than the cure.
Risk management is a proactive attempt to identify potential risks and incidents before they happen in order to develop prevention and response strategies.
Risk Management: Benefits
- Increase the likelihood of the Agency achieving strategic and business objectives;
- Encourage a high standard of accountability at all levels of the organisation;
- Support more effective decision making through better understanding of risk exposures;
- Create an environment that enables the Agency to deliver timely services and meet performance objectives in an efficient and cost effective manner;
- Safeguard the Agency’s assets — human, property and reputation; and
- Meet compliance and governance requirements.
Agency Approach
- Requirements:
- CAC Act/PGPA Act;
- NDIS — Risk Management Rules
- APRA CPS 220 (Board policy)
- Risk is part of the way we do business in the Agency, not another thing to do
Agency Approach - Components
- Risk Management Framework
- Risk Management Strategy
- Risk Management Manual — Tools and templates
- Intranet site
- Risk Management Champions
Page 206 of 292
Risk Management Framework
- Systematic approach to risk identification & management
- Consistent risk assessment criteria
- Accurate and concise risk information, for decisions
- Cost effective and efficient risk treatment strategies
- Ensure risk exposure remains within acceptable level
- Includes the culture, processes and structures that are directed towards realising potential opportunities while managing adverse effects
Page 207 of 292
Risk Management Strategy
- Covers:
- Risk Governance
- Processes to identify, mitigate and control risks
- Monitoring and reporting risks
- Risk communication and risk culture
- Roles and Responsibilities
- Review process
Governance Arrangements
[Image not converted to Markdown – “Governance Arrangement Diagram” – check the source PDF page for the actual content]
COAG Disability Reform Council
Sustainability Committee - NDIA Board - External Auditor (ANAO)
Scheme Actuary - Audit and Risk Committee - Internal Audit/Independent Review
Chief Executive Officer - Independent Advisors (e.g. APRA, Review Actuary)
Chief Risk Officer - Executive Management Team - Assurance, Audit and Risk Committee
NDIA staff
Commonwealth Minister (CAC/PGPA Act)
Page 209 of 292
Risk Management Processes
Communicate and consult
| Risk context | Risk identification | Risk analysis | Risk evaluation | Risk treatment |
|---|---|---|---|---|
| Objectives | What can happen? | Review controls | Evaluate risks | Further mitigation activities |
| Stakeholders | How can it happen? | Assess consequence | Rank risks | Risk escalation, monitoring and assurance |
| Assessment criteria | Assess likelihood | Risk acceptance (yes/no) | ||
| Define key risk elements | Determine ‘current’ risk level | Determine ‘target’ risk level |
Monitor and review
Monitoring & Reporting
- Three levels of monitoring
- Strategic risks
- Operational risks
- Project risks
Integrated Risk Management
FOI 20/21-0879
[redacted]
National disability insurance Agency
Strategic Plan
| Strategic Risks |
|---|
| Strategic Risk Management |
| Operational Risks |
| Operational Risk Management |
| Significant Projects |
| Corporate Business Plan | | Divisional Business Plans | | Branch/Site Business Plans |
Business as usual Significant projects
| Individual Performance Agreements |
Page 212 of 292
Reporting & Monitoring
Strategic Risks
- Strategic Risk Treatment Actions Report (quarterly)
- Risks to the delivery of strategic plans or achievement of corporate goals
Operational Risks
- Operational Risk Treatment Actions Report (monthly)
- Risks to the delivery of day to day operations or services
- Specialist risk assessments (e.g fraud, WHS)
Project Risks
- Project Risk Treatment Actions Report (fortnightly)
- Risks to the delivery of individual projects
CRO reviews and prepares summary report for CEO, Board, Strategic Risk Committee, Audit Fraud Risk and Compliance Committee, and/or Audit and Risk Committee as appropriate
Page 213 of 292
Strategic Risks
- People with disability are in control and have choices, based on the UN Convention on the Rights of Persons with Disabilities
-
The Agency fails to build the capacity of people with disability to exercise choice and control
-
The Agency fails to promote the independence and social and economic participation of people with disability
-
The Agency fails to establish mechanisms which effectively measure social and economic outcomes and exercise of choice and control
Page 214 of 292
Strategic Risks (2)
The National Disability Insurance Scheme (NDIS) is financially sustainable and governed using insurance principles
- The Agency fails to meet support package needs within available funding envelopes
- The Agency fails to deliver operational capability within available funding envelopes
- The Agency fails to identify and mobilise IT resources to meet the needs of actuarial and management reporting
- The scope and scale of participation exceeds Scheme design — more people with permanent and significant disabilities
- The scope and scale of supports exceed Scheme design — cost of reasonable and necessary supports
- A reduction occurs in the level of family and community supports and in personal responsibility
- The Agency fails to invest in a lifetime approach, including early intervention
Strategic Risks (3)
The community has ownership, confidence and pride in the National Disability Insurance Scheme and the National Disability Insurance Agency
- Stakeholders perceive that the Scheme has failed to meet the needs of people with disability and/or is too costly
- Sufficient competent providers fail to emerge to meet the new and expanded demand for services
- Sufficient qualified provider staff fail to emerge to meet the new and expanded demand for services
- The Agency fails to meet its reporting obligations to Governments and the Commonwealth Parliament
- The Agency fails to establish an organisational culture and management systems that foster accountability and continuous learning
- The Agency fails to attract and retain sufficient talented leaders and staff to meet the challenges of start-up and/or full scheme rollout
Progress
- Strategy
- Strategic risks
- Framework
- Risk Management Manual
- Intranet site
- Risk Management Champions
- Business Planning processes
Your role
- Be familiar with the Agency’s risk management strategy and policy;
- Alert managers to the presence of risks and participate in their management; and
- Use the tools available to identify and manage risks in the workplace
- Give us feedback
Fraud Control
“Dishonestly obtaining a benefit, or causing a loss, by deception or other means”
Fraud against the Commonwealth
Includes (but is not limited to):
- Theft
- Accounting fraud (false invoices, misappropriations etc.)
- Unlawful use of, or unlawfully obtaining, property, equipment, material or services
- Causing a loss, or avoiding and/or creating a liability
- Providing false or misleading information to the Commonwealth, or failing to provide it when there is an obligation to do so
- Misuse of Commonwealth assets, equipment or facilities
- Making or using false, forged or falsified documents
- Wrongfully using Commonwealth information or intellectual property
- Bribery, corruption or abuse of office
Page 220 of 292
Fraud and Error
-
Fraud is a criminal offence
-
Fraud is based on deception
-
An error is not fraud
-
If you make a mistake — Tell your supervisor about the error — Follow it up with an email — Keep a record of the email
Agency’s Approach to Fraud Control
- Fraud Control Framework & Plan
- APS Values and Code of Conduct
- Fraud Policy Statement
- Fraud Awareness Education
- Financial rules
- Governance arrangements — Prevention and detection strategies
Internal Fraud
- Involves staff
- Examples:
- Falsifying a medical certificate or statutory declaration
- Cheating on a flex sheet
- Unauthorised disclosure of information
- Claiming travel allowance you are not entitle to
- Failing to record, or incorrect recording of, leave
- Misuse of Cabcharge vouchers
- Use of the Corporate credit card for personal gain
… and more
— Using office printers for non-work related printing
— Internet — unreasonable personal use of internet, including emails and communicator/Lync
— Failing to secure portable assets such as TVs during relocation/renovations
— Personal use of pool vehicles/fuel cards
— Stealing laptops/phones/GPS devices
False information
- Providing false information includes:
- Backdating and post signing of records
- Altering funding agreements/contracts etc. after the event
- Submitting information in reports, acquittals, returns etc. that the author knew did or did not happen, and is untrue
Internal Fraud - Penalties
-
Internal fraud can result in criminal prosecution, and/or investigation under the APS Code of Conduct.
-
Penalties can include:
- Dismissal
- Demotion
- Loss of Commonwealth contributed superannuation
- Criminal conviction
- Imprisonment
Page 226 of 292