Introduction
For charitable and non-profit organisations, financial resources are not the most valuable asset they possess. Public trust is.
Whenever a donor contributes to a humanitarian or development programme, they are doing far more than transferring financial resources. They are placing confidence in the organisation's ability to manage those resources responsibly, ensure they reach their intended beneficiaries, and deliver the social impact that has been promised.
For this reason, fraud and corruption represent far more than financial losses. They can erode public confidence, weaken relationships with beneficiaries and partners, discourage future donors, jeopardise grant funding, expose organisations to legal consequences, and inflict long-term reputational damage that may take years to rebuild.
In the previous article, we explored Whistleblowing as the governance mechanism that enables organisations to identify misconduct and emerging risks at an early stage by encouraging employees, volunteers, partners, and beneficiaries to report concerns safely and responsibly.
This article moves one step further.
Rather than focusing on how misconduct is reported, it examines how organisations can reduce the likelihood of fraud and corruption occurring in the first place by establishing strong governance, effective internal controls, robust risk management, and a culture of organisational integrity.
Today, preventing fraud and corruption is no longer regarded as the sole responsibility of finance departments or internal auditors. It has become a fundamental element of organisational governance, Enterprise Risk Management (ERM), and compliance. Boards of Trustees, executive leadership, employees, volunteers, implementing partners, contractors, suppliers, and even donors all play important roles in protecting organisational resources.
Likewise, international funding organisations no longer assess charities simply by reviewing whether an Anti-Fraud Policy exists.
Instead, they examine whether the organisation has established practical systems capable of preventing misconduct, detecting irregularities at an early stage, responding appropriately when incidents occur, and continuously strengthening internal controls based upon lessons learned.
For this reason, many organisations draw upon internationally recognised governance frameworks such as the COSO Fraud Risk Management Framework, ISO 37001 (Anti-Bribery Management Systems), and ISO 37301 (Compliance Management Systems) when developing mature fraud prevention programmes.
This article explains the nature of fraud and corruption within charitable organisations, explores why non-profit institutions remain vulnerable to these risks, and presents the governance principles, preventive controls, and organisational practices required to protect donor resources, strengthen institutional integrity, and enhance donor confidence.
First: What Do Fraud and Corruption Mean in Non-Profit Organisations?
Although the terms fraud and corruption are frequently used together, they represent different concepts from a governance and risk management perspective.
Fraud refers to any deliberate act intended to obtain an unlawful benefit through deception, manipulation, concealment of information, falsification, or misuse of organisational resources.
Such benefits may involve money, assets, services, information, or other forms of personal advantage.
Corruption, by contrast, is a broader concept involving the abuse of entrusted power for private gain.
It may take many forms, including:
Bribery.
Abuse of authority.
Nepotism or favouritism.
Conflicts of interest.
Undue influence over organisational decisions.
Improper procurement practices.
Misuse of organisational position.
Within charitable organisations, these risks extend well beyond financial transactions.
Fraud and corruption may affect:
Programme implementation.
Procurement and contracting.
Recruitment.
Beneficiary selection.
Grant management.
Reporting.
Asset management.
Information management.
Partnership arrangements.
Consequently, Anti-Fraud and Anti-Corruption systems should never be viewed solely as investigative mechanisms.
Their primary objective is to establish governance arrangements that reduce opportunities for misconduct before it occurs through clear policies, effective controls, accountability, and an organisational culture built upon integrity.
Second: Why Are Charitable Organisations Not Immune to Fraud?
One of the most common misconceptions within the non-profit sector is that humanitarian values and ethical missions provide sufficient protection against fraud.
Practical experience demonstrates otherwise.
Any organisation, regardless of its charitable purpose, may become vulnerable whenever appropriate governance and internal controls are absent.
Fraud risks often increase where organisations experience:
Rapid organisational growth without corresponding improvements in governance.
Excessive reliance on personal trust rather than institutional procedures.
Concentration of financial or operational authority in a small number of individuals.
Weak segregation of duties.
Limited internal audit capacity.
Infrequent fraud risk assessments.
Poor documentation of financial or operational activities.
Pressure to deliver projects rapidly at the expense of established controls.
For this reason, mature organisations do not build governance systems upon assumptions of personal integrity alone.
Instead, they establish internal controls that protect honest individuals while reducing opportunities for misconduct by anyone who may seek to exploit organisational weaknesses.
Third: Fraud Prevention Begins with Leadership (Tone at the Top)
International governance standards consistently recognise that the strongest defence against fraud is not technology or written procedures—it is leadership.
This principle is widely known as Tone at the Top.
It describes the values communicated by organisational leaders through their decisions, behaviour, and daily actions.
When Boards of Trustees and executive leaders consistently comply with organisational policies, manage conflicts of interest transparently, demonstrate accountability, and apply governance standards equally to everyone, they establish an organisational culture in which integrity becomes the expected norm.
Conversely, when senior leaders tolerate exceptions, overlook misconduct because of personal relationships, or apply standards inconsistently, they weaken every internal control regardless of how comprehensive those controls may appear on paper.
For this reason, effective Anti-Fraud and Anti-Corruption programmes begin with ethical leadership before they depend upon policies, procedures, technology, or investigations.
Fourth: The Fraud Triangle—Why Does Fraud Occur?
One of the most widely recognised models for understanding occupational fraud is the Fraud Triangle, developed by criminologist Donald Cressey.
The model explains that fraud generally becomes possible when three conditions exist simultaneously.
Pressure
Individuals may experience financial, professional, or personal pressures that increase the temptation to seek improper benefits.
Pressure alone does not cause fraud.
However, it often represents one contributing factor.
Opportunity
Opportunity is the element over which organisations exercise the greatest control.
Weak governance, inadequate supervision, poor segregation of duties, and ineffective internal controls create opportunities that make fraudulent behaviour significantly easier.
Strengthening internal controls therefore remains one of the most effective methods of reducing fraud risk.
Rationalisation
Individuals sometimes justify misconduct by convincing themselves that their actions are acceptable.
Common justifications include believing they deserve additional compensation, intending to repay funds later, or assuming that the organisation will not suffer significant harm.
Developing a strong organisational culture based upon integrity reduces the likelihood that such rationalisations will become socially acceptable within the workplace.
The Fraud Triangle therefore demonstrates that effective fraud prevention depends not on distrusting people, but on designing governance systems that reduce opportunities for misconduct while reinforcing ethical organisational behaviour.
Fifth: The Most Common Fraud and Corruption Scenarios in Non-Profit Organisations
Although the nature of fraud varies between organisations, governance reviews and international audit reports consistently identify several recurring scenarios within the non-profit sector.
Understanding these risks does not imply that every organisation will experience them. Rather, it enables organisations to strengthen preventive controls before weaknesses are exploited.
Financial Fraud
Financial fraud remains one of the most common forms of organisational misconduct and may include:
Manipulation of expense claims or reimbursement requests.
Submission of false invoices or supporting documentation.
Payments for projects or activities that were only partially implemented.
Misuse of organisational bank accounts or payment cards.
Manipulation of petty cash or cash advances.
Falsification of accounting records.
The likelihood of financial fraud increases significantly where a single individual controls multiple stages of financial processing without independent review.
Procurement and Contracting Fraud
Procurement activities represent one of the highest-risk operational areas within charitable organisations.
Common examples include:
Awarding contracts without fair competition.
Collusion between employees and suppliers.
Artificially inflated purchase prices.
Acceptance of goods or services below agreed specifications.
Splitting contracts to avoid financial approval thresholds.
Accepting gifts or personal benefits that influence procurement decisions.
Leading organisations therefore implement transparent procurement procedures based upon fair competition, documented approvals, segregation of duties, and independent verification of contract performance.
Programme Delivery Fraud
Fraud may also occur during the implementation of humanitarian or development programmes.
Examples include:
Inflating beneficiary numbers.
Registering ineligible beneficiaries.
Reporting activities that were never delivered.
Submitting inaccurate programme reports.
Exaggerating programme outcomes or impact indicators.
Even where such actions are intended to demonstrate programme success or satisfy donor expectations, they represent serious governance failures that undermine institutional credibility and donor confidence.
Misuse of Organisational Assets
Organisational assets extend well beyond financial resources.
They include:
Vehicles.
Information technology equipment.
Software licences.
Office facilities.
Machinery and equipment.
Databases.
Digital platforms and subscriptions.
Using these resources for personal purposes outside authorised organisational activities constitutes misuse of assets, even where direct financial losses appear limited.
Conflicts of Interest
Conflicts of interest do not necessarily constitute fraud in themselves.
However, unmanaged conflicts frequently create conditions in which fraudulent or unethical decisions become more likely.
Examples include:
Awarding contracts to businesses owned by relatives without proper disclosure.
Participating in decisions that generate personal financial benefit.
Influencing supplier or beneficiary selection to favour personal interests.
For this reason, formal Conflict of Interest Policies have become one of the most important preventive governance tools within the non-profit sector.
Cyber Fraud
Digital transformation has introduced new forms of fraud that can be equally damaging to charitable organisations.
Examples include:
Business Email Compromise (BEC) schemes impersonating senior executives.
Fraudulent payment instructions.
Fake fundraising campaigns using the organisation's identity.
Counterfeit donation websites or QR codes.
Theft of donor or beneficiary information.
Artificial intelligence-generated phishing attacks.
Accordingly, cybersecurity, identity management, secure payment verification, and digital governance have become essential components of modern Anti-Fraud programmes.
Sixth: Recognising Early Warning Signs (Red Flags)
Fraud rarely occurs without warning.
In many cases, behavioural, financial, or operational indicators appear long before significant losses occur.
While these indicators do not automatically prove misconduct, they should prompt further review and appropriate investigation.
Financial Indicators
Examples include:
Repeated invoices with identical amounts.
Transactions processed outside normal approval procedures.
Unexplained inventory discrepancies.
Delays in clearing cash advances.
Frequent adjustments to accounting records without adequate explanation.
Operational Indicators
Potential warning signs include:
Excessive concentration of authority in one individual.
Resistance to audits or independent reviews.
Weak documentation of approvals.
Employees who consistently refuse annual leave or temporary delegation of responsibilities.
Behavioural Indicators
Behavioural changes may also warrant attention, such as:
Unusual secrecy regarding organisational information.
Refusal to share operational data.
Regular bypassing of established procedures under the justification of urgency.
Unusually close relationships with suppliers or beneficiaries.
The presence of these indicators should never result in premature conclusions.
Instead, organisations should review controls, verify processes, and address potential weaknesses before they develop into more serious governance failures.
Seventh: Fraud Risk Assessment
Modern organisations increasingly focus on managing fraud risk proactively rather than responding only after misconduct has occurred.
The starting point is a structured Fraud Risk Assessment, designed to identify the areas most vulnerable to fraud before incidents arise.
A typical assessment includes:
Identifying critical organisational assets and processes.
Identifying credible fraud scenarios.
Assessing the likelihood of each risk.
Evaluating the potential financial, operational, legal, and reputational impact.
Reviewing existing control measures.
Determining the level of residual risk.
Designing additional controls where necessary.
Fraud Risk Assessments should be reviewed periodically and updated whenever organisations introduce new programmes, partnerships, technologies, funding arrangements, or operational structures.
Eighth: The Fraud Management Lifecycle
Leading organisations treat fraud management as a continuous governance process rather than a reactive investigation.
The typical Fraud Management Lifecycle consists of the following stages:
Risk Identification
↓
Risk Assessment
↓
Preventive Controls
↓
Early Detection
↓
Investigation
↓
Corrective Response
↓
Organisational Learning and Continuous Improvement
By adopting this lifecycle, organisations transform fraud prevention into an ongoing management process that evolves alongside changing operational risks and organisational growth.
Ninth: How Can an Effective Fraud Risk Management System Be Built?
Modern organisations no longer rely solely upon investigations after fraud has occurred.
Instead, they establish integrated governance systems designed to reduce opportunities for fraud, identify irregularities at an early stage, and respond consistently whenever incidents arise.
Such systems are built upon several complementary layers of internal control.
Segregation of Duties
Segregation of duties remains one of the most effective fraud prevention controls available to any organisation.
No single individual should be responsible for initiating, approving, receiving, paying for, and reviewing the same transaction.
For example, the person who:
Requests a purchase,
Approves the purchase,
Receives the goods,
Authorises payment, and
Reviews the supporting documentation,
should never be the same individual.
Distributing responsibilities across multiple authorised personnel significantly reduces opportunities for manipulation while increasing the likelihood that irregularities will be detected promptly.
Financial Controls
Strong financial controls provide another essential layer of protection.
Typical examples include:
Clearly defined financial approval thresholds.
Independent review of high-value transactions.
Regular bank reconciliations.
Periodic asset verification and inventory counts.
Review of cash advances and petty cash.
Complete documentation supporting every financial transaction.
Independent verification of sensitive financial activities.
These controls reduce both fraud risk and operational error while strengthening donor confidence.
Technology and Data Analytics
Digital systems have become increasingly important in fraud prevention.
Modern organisations make use of technologies such as:
Electronic transaction records.
User access controls.
Comprehensive Audit Trails.
Automated alerts for unusual transactions.
Exception Reporting.
Data analytics to identify abnormal patterns.
Continuous Monitoring of high-risk activities.
Artificial intelligence and advanced analytics are also increasingly supporting early detection by identifying unusual financial or operational behaviour that may otherwise remain unnoticed, particularly within organisations managing large programmes or multiple funding streams.
Tenth: Third-Party Due Diligence
International experience consistently demonstrates that many fraud cases involve external parties such as suppliers, contractors, consultants, or implementing partners.
For this reason, Third-Party Due Diligence has become an essential element of modern Anti-Fraud programmes.
Before entering into contractual relationships, organisations should assess factors including:
Legal identity and registration.
Ownership and beneficial ownership where appropriate.
Professional reputation and previous performance.
Potential conflicts of interest.
Applicable sanctions or regulatory restrictions where relevant.
Financial and technical capacity.
Due diligence should not end once a contract has been signed.
Organisations should continue monitoring supplier and partner performance throughout the relationship to ensure continued compliance with organisational standards and contractual obligations.
Eleventh: Fraud Response Planning
Even the strongest governance systems cannot eliminate fraud risk entirely.
Consequently, every organisation should establish a structured Fraud Response Plan describing how suspected incidents will be managed.
A typical response process includes:
Contain the Incident
↓
Secure Evidence
↓
Notify the Appropriate Authorities Within the Organisation
↓
Conduct an Independent Investigation
↓
Implement Corrective or Legal Action Where Appropriate
↓
Recover Funds or Assets Where Possible
↓
Analyse Root Causes
↓
Strengthen Controls to Prevent Recurrence
Having a clearly defined response plan reduces organisational disruption, protects evidence, strengthens investigative integrity, and demonstrates responsible governance to donors and regulators.
Twelfth: The Role of the Board and Executive Leadership
Preventing fraud is not solely the responsibility of finance departments or internal auditors.
Responsibility begins with organisational leadership.
The Board of Trustees should:
Approve the Anti-Fraud and Anti-Corruption Policy.
Oversee fraud risk management.
Review fraud-related reports.
Ensure the independence of internal audit.
Monitor implementation of corrective actions.
Promote an organisational culture of integrity.
Executive management is responsible for translating governance expectations into daily operational practice through:
Promoting ethical behaviour.
Providing staff training.
Implementing internal controls.
Addressing weaknesses identified through audits or whistleblowing reports.
Monitoring fraud-related performance indicators.
When Boards and executive leadership fulfil these complementary responsibilities, protecting donor resources becomes an organisation-wide commitment rather than the responsibility of a single department.
Thirteenth: Internal Audit—The Line of Defence Before Losses Occur
Internal audit represents one of the most valuable governance mechanisms available to charitable organisations.
Its purpose extends far beyond identifying errors after they occur.
An effective internal audit function should:
Evaluate the effectiveness of internal controls.
Review compliance with organisational policies.
Assess operational and financial risks.
Recommend improvements.
Monitor implementation of corrective actions.
To remain effective, internal audit should operate independently and report to the Audit Committee or Board of Trustees rather than executive management wherever practical.
Equally important, audit findings should lead to measurable improvements in governance systems rather than remaining solely within audit reports.
Fourteenth: The Three Lines Model
Many international organisations now adopt the Three Lines Model as a recognised governance framework for managing organisational risk.
The model distributes responsibility across three complementary levels.
First Line – Operational Management
Operational departments are responsible for day-to-day activities, compliance with procedures, and applying internal controls during programme implementation.
Fraud prevention begins with consistent operational discipline.
Second Line – Risk Management and Compliance
Risk and compliance functions establish organisational policies, monitor compliance, assess emerging risks, provide guidance, and strengthen internal controls as organisational circumstances evolve.
Third Line – Internal Audit
Internal audit provides independent assurance regarding the effectiveness of governance, risk management, and internal controls.
By reporting objectively to the Board or Audit Committee, internal audit provides leadership with independent confidence that organisational safeguards remain effective.
Together, these three lines create a balanced governance system that integrates prevention, oversight, independent assurance, and continuous improvement.
Fifteenth: How Do Donors Assess Anti-Fraud and Anti-Corruption Systems?
International donors no longer regard the existence of an Anti-Fraud and Anti-Corruption Policy as sufficient evidence of institutional readiness.
Instead, they seek practical assurance that fraud prevention has been fully integrated into the organisation's governance, risk management, financial controls, procurement systems, and organisational culture.
During Organisational Readiness Assessments, Due Diligence Reviews, and donor compliance audits, funding organisations commonly examine whether the organisation has established:
A formally approved Anti-Fraud and Anti-Corruption Policy.
Regular Fraud Risk Assessments covering financial and operational activities.
Appropriate segregation of duties across financial and procurement processes.
A comprehensive Conflict of Interest Policy.
A trusted Whistleblowing System supported by Non-Retaliation arrangements.
Independent Internal Audit arrangements.
Clearly documented fraud investigation procedures.
Strong procurement governance and supplier due diligence processes.
Mandatory fraud awareness training for employees, volunteers, and Board members.
Active oversight by the Board of Trustees or Audit Committee.
Processes for reviewing incidents and strengthening controls based upon lessons learned.
These expectations are not intended to increase administrative burden.
Rather, they demonstrate an organisation's ability to protect donor resources, maintain public confidence, and manage charitable funds responsibly.
Sixteenth: Building an Organisational Culture That Resists Fraud
An organisation may implement excellent policies, sophisticated financial systems, and advanced technologies, yet still remain vulnerable if it fails to establish a genuine Integrity Culture.
Integrity Culture exists when ethical behaviour becomes part of everyday organisational practice rather than simply a compliance requirement.
Employees follow procedures not because they fear disciplinary action, but because they recognise their shared responsibility for protecting the organisation's mission, beneficiaries, and donor resources.
Creating such a culture requires leadership commitment at every level.
It is strengthened through:
Ethical leadership by the Board and executive management.
Consistent application of organisational policies.
Fair and transparent decision-making.
Continuous staff awareness and training.
Responsible whistleblowing.
Accountability for misconduct regardless of seniority.
Organisational learning following incidents.
When employees observe that integrity applies equally to everyone, ethical behaviour gradually becomes embedded within the organisation's culture rather than imposed through supervision alone.
Seventeenth: Transparency—The Most Valuable Investment in the Non-Profit Sector
Transparency is often misunderstood as simply publishing organisational information.
In reality, it represents one of the most valuable long-term investments any charitable organisation can make.
Modern donors wish to understand not only whether funds were spent, but also:
How they were used.
Who approved and monitored expenditure.
What outcomes were achieved.
Which governance arrangements protected those resources.
Leading organisations therefore promote transparency by:
Publishing annual and financial reports.
Disclosing governance and risk management arrangements.
Explaining internal control mechanisms.
Reporting programme performance and impact.
Communicating how significant incidents have been managed in accordance with applicable legal and governance requirements.
Transparency does not require disclosure of every operational detail.
Instead, it involves providing meaningful information that reinforces accountability, strengthens public confidence, and demonstrates responsible stewardship of charitable resources.
Eighteenth: Indicators of Organisational Maturity in Fraud Prevention
The maturity of an organisation's Anti-Fraud programme can be evaluated through several practical governance indicators.
Examples include:
A formally approved Anti-Fraud and Anti-Corruption Policy.
Regular Fraud Risk Assessments.
Clearly documented segregation of duties.
Integration of fraud prevention within governance and Enterprise Risk Management.
Ongoing fraud awareness training for employees, volunteers, and Board members.
A trusted Whistleblowing mechanism.
Independent Internal Audit activities.
Continuous improvement based upon investigation findings.
Active oversight by the Board or Audit Committee.
A regularly updated Fraud Risk Register.
Leading organisations also monitor measurable Key Performance Indicators (KPIs) to evaluate the effectiveness of fraud prevention arrangements.
Examples include:
Average time required to detect suspected fraud.
Average investigation completion time.
Percentage of personnel completing annual fraud awareness training.
Percentage of suppliers completing due diligence procedures.
Percentage of Internal Audit recommendations implemented.
Recovery rate for misappropriated funds or assets.
Number of governance improvements arising from investigations.
Frequency of recurring fraud incidents.
Monitoring these indicators enables organisations to evaluate the effectiveness of governance arrangements objectively while supporting continuous organisational improvement.
Before Moving to the Next Article...
If your organisation wishes to strengthen its institutional readiness, consider beginning with the following practical actions:
✓ Formally adopt an Anti-Fraud and Anti-Corruption Policy.
✓ Conduct regular Fraud Risk Assessments.
✓ Strengthen segregation of duties across financial and operational processes.
✓ Enhance procurement governance and contract management.
✓ Implement a comprehensive Conflict of Interest Policy.
✓ Apply Third-Party Due Diligence to suppliers and implementing partners.
✓ Maintain trusted Whistleblowing arrangements.
✓ Deliver regular fraud awareness training for employees, volunteers, and Board members.
✓ Monitor fraud-related performance indicators.
✓ Use investigation findings to strengthen governance systems continuously.
These practical measures establish the foundations of a resilient organisation capable of protecting donor resources while strengthening accountability and public confidence.
Quick Self-Assessment
Consider the following questions:
□ Does our organisation have a formally approved Anti-Fraud and Anti-Corruption Policy?
□ Do we conduct regular Fraud Risk Assessments?
□ Are responsibilities appropriately segregated across financial processes?
□ Do we apply a Conflict of Interest Policy consistently?
□ Do suppliers and partners undergo appropriate Due Diligence?
□ Do we maintain a trusted Whistleblowing mechanism?
□ Does the Board or Audit Committee oversee fraud risk management?
□ Do investigation outcomes result in improvements to governance systems?
If you answered "No" to more than two of these questions, your organisation may need to strengthen this critical area of institutional readiness.
Conclusion
Protecting donor funds cannot rely upon trust alone, nor can it be achieved simply through the existence of policies and procedures.
It requires an integrated governance framework that combines good governance, Enterprise Risk Management, effective internal controls, organisational integrity, transparency, accountability, and continuous improvement.
International best practice consistently demonstrates that the organisations most successful in preventing fraud are not those that investigate incidents most effectively after they occur, but those that invest continuously in prevention, strengthen internal controls, use technology and data analytics for early detection, encourage responsible reporting, and treat every incident as an opportunity to improve organisational resilience.
Equally important, fraud prevention is not the responsibility of finance departments or internal auditors alone.
It begins with the Board of Trustees, extends through executive leadership, employees, volunteers, implementing partners, and contractors, and ultimately becomes a shared organisational responsibility.
This article forms the seventh chapter in the series "Building a Funding-Ready and Institutionally Compliant Charity." It has explored one of the most important governance functions for protecting charitable resources, strengthening donor confidence, and supporting long-term organisational sustainability.
Next Article
Having explored how organisations can protect charitable resources from fraud and corruption, the next article examines another cornerstone of good governance:
Conflict of Interest: How Can Your Organisation Protect the Integrity of Its Decisions?
The next article will explain how charitable organisations can identify, disclose, manage, and monitor conflicts of interest while strengthening governance, protecting impartial decision-making, and meeting the expectations of international donors and recognised governance standards.