A written Fraud Risk Management Policy is essential to convey the expectations of the board and senior management. This policy should serve as a solid foundation by documenting and regularly updating the organization’s overarching FRM program.
Core Policy Components:
  • Governance Framework: Defining the roles and responsibilities of personnel at all levels regarding fraud risk governance.
  • Standards of Conduct: Explicitly stating the organization’s affirmation of “zero tolerance” for fraud.
  • Documentation Standards: Maintaining thorough documentation of policies, standard operating procedures, manuals, and service level agreements (SLAs).
  • Incentive Alignment: Designing corporate governance to prevent scandals and potential civil or criminal liability through fair and consistent enforcement of consequences.