Scottish Public Finance Manual

The Scottish Public Finance Manual (SPFM) is issued by the Scottish Ministers to provide guidance on the proper handling and reporting of public funds.


Fraud

Scope

This section gives the principles on counter fraud and the prevention, detection, reporting and handling of fraud.

Applicability

This section is applicable to all organisations to which the Scottish Public Finance Manual (SPFM) is directly applicable, including constituent parts of the Scottish Administration and bodies sponsored by the Scottish Government. NHS Boards (including all Special Boards and Agencies) are subject to the specific arrangements set out in the NHS Scotland Counter Fraud Strategy 2023-2026 and the Partnership Agreement between NHS Boards and NHS Scotland Counter Fraud Services.

Definitions:

Shall/must: denotes a requirement; a mandatory element
Should: denotes a recommendation; an advisory element
May: denotes approval
Might: denotes a possibility
Can: denotes both capability and possibility
Is/are: denotes a description

Links to relevant guidance:

Principles:

SG guidance:

  • Is available on the SG website and the below Public Sector guidance

Public sector bodies guidance:

Review/Update

Lead area: Scottish Government Directorate for Internal Audit and Assurance; Internal Audit Division – Counter Fraud Branch.

For update/review of this principle please refer to the Guidance and Procedure available on the SG intranet or from the Governance and Accountability team, this includes information on ministerial approval.

Accessibility guidance is available on the SG intranet.

Background

The term "fraud" is commonly used to describe a wide variety of behaviour such as fraud by deception, forgery, false representation, and deliberate omission or concealment of information. For the purposes of this document, the term ‘fraud’ includes any circumstances where a person or persons, deliberately and with the intent to benefit themselves or another person:

  • makes a false representation (including implied representation) or statement;
  • withholds or omits material information;
  • fails to act;
  • tenders a forged or counterfeit document as genuine;
  • abuses a position of trust;
  • interferes with or alters information held.

The description of fraud includes circumstances where two or more people collude or conspire, and where fraud is attempted but either prevented or detected before any loss is incurred.

Managing the risk of fraud

Accountable Officers are responsible for establishing and maintaining effective systems of internal control that support the achievement of the organisation's policies, aims and objectives. The systems of internal control are designed to respond to and manage the whole range of risks that an organisation faces. Managing the risk of fraud - both internal and external - should be seen in the context of the management of this wider range of risks. See the section of the SPFM on Risk Management.

In broad terms, managing the risk of fraud involves:

  • assessing the organisation's overall vulnerability to fraud;
  • identifying the area's most vulnerable to fraud risk;
  • evaluating the scale of fraud risk;
  • responding to the fraud risk; and
  • measuring the effectiveness of the fraud risk strategy.

Guidance on managing the risk of fraud for public bodies from the International Public Sector Fraud Forum can be found at Guide To Managing Fraud For Public Bodies.

The key to an organisation’s effective management of fraud risk is in the undertaking of a suitable Fraud Risk Assessment (FRA). An appropriate FRA will ensure an objective approach to identifying the highest risks of fraud faced by the organisation or operational activity being assessed, the robust assessment of current systems of control to prevent and detect fraud, the actions required to improve counter fraud effectiveness where risk exposure remains high despite current controls. Guidance on undertaking an effective Fraud Risk Assessment can be found at - Public Sector Fraud Authority - Practice Note - Fraud Risk Assessment

Promoting an anti-fraud culture

In addition to maintaining effective systems of internal control, public sector organisations should also promote an anti-fraud culture. Organisations will make a clear commitment to ethical standards in public life and develop a fraud policy statement in order to communicate their approach to preventing, detecting, and deterring fraud. The Scottish Government's Counter Fraud Strategy and Counter Fraud Policy are reproduced at Annex 1 and Annex 2 respectively.

Prevention and detection

All staff are responsible for the prevention and detection of fraud but the prime responsibility for designing, operating and reviewing control systems rests with the managers involved. Overall responsibility for ensuring that such systems and procedures are in place rests with Accountable Officers, but managers must take responsibility for setting up proper systems of control and for ensuring that there is strict compliance. Managers should consult the organisation's finance function and internal audit where new control procedures are being set up or significant changes to existing procedures are being proposed, and ideally counter fraud colleagues where controls are designed specifically to mitigate fraud risk.

Appropriate preventive and detective controls should be put in place. Preventive controls are designed to limit the possibility of an undesirable outcome e.g. fraud, being realised whilst detective controls are designed to spot errors, omissions and fraud after the events have taken place. There are a range of controls - e.g. physical checks, reconciliations, supervisory checks, segregation and rotation of duties, and clear roles and responsibilities - which address risks, including that of fraud. Managers should consider, in consultation with the organisation's finance function and internal audit as appropriate, which controls are the most appropriate in their particular circumstances.

Systems of control

Systems with proper controls lessen the opportunity for fraud. Managers with responsibility for awarding contracts (including minor contracts), making payments, authorising grants and the like must ensure that they have well understood procedures for authorising contracts and other approvals. It is important that there are robust systems of control in place, which comply with good financial management and procurement principles.

The degree of control within a system should be proportional to the risks involved, the consequences of failure and the resource costs of eliminating or reducing these factors. Procedures set up to prevent and detect fraud must be carefully followed and monitored. Important considerations therefore are the sections of the SPFM on Checking Financial Transactions and on Risk Management.

The majority of frauds are successful due to failure to comply with existing control systems. Both internal and external auditors have a role in carrying out independent reviews of systems and the adequacy of controls in place, though managers have the prime responsibility for ensuring their systems are sound and that they are operating as intended. In practice, therefore it is good initial systems design coupled with subsequent supervisory checking and monitoring and alertness to the risks and pointers to fraud that are the principal means of detection.

Guidance to managers on the risks which they face and on the procedures they should adopt to avoid fraud or financial irregularity is included in  Guide To Managing Fraud For Public Bodies and the Public Sector Fraud Authority - Practice Note - Fraud Risk Assessment. Key factors in the design of systems and controls will be the nature of the activity, the risks involved and any history of fraudulent activity, whether internal or external.

Reporting suspicions

Organisations must put in place avenues for reporting suspicions of fraud. Staff should be encouraged to report such suspicions either to their line managers, to the organisation's internal audit (or specialist fraud unit), to the organisation's finance function or possibly to a dedicated email or online form set up for the purpose. In developing their fraud reporting arrangements, organisations should take into account the Public Interest Disclosure Act 1998, which provides remedies for workers who are dismissed or subject to detriment for making qualifying disclosures. Reporting arrangements should be set out in detail in the organisation's fraud policy statement.

Responding to fraud

Organisations should draw up fraud response plans to ensure that timely and effective action is taken in the event of a fraud. Such plans can also help minimise losses and increase the chances of a successful investigation. The fraud response plan should reflect the risk assessment undertaken; include guidance about how and when to make a report to Police Scotland; and should be reviewed periodically. 

Organisations are responsible for undertaking thorough investigations where fraud is suspected and for taking the appropriate legal and/or disciplinary action in all cases where that would be justified. Appropriate disciplinary action should also be taken where supervisory, or management failures have occurred. Fraud investigation is a specialised area of expertise, and organisations should ensure that those tasked with any investigation have received appropriate training. Investigations should consider any control failures and make recommendations on systems and procedures to minimise the risk of a recurrence. Legal advice should be taken where necessary.

Notification

All cases of actual or attempted fraud should be notified to the organisation's Audit Committee - see the section of the SPFM on Audit and Assurance Committees. External auditors will be made aware of such cases via the reports to audit committees, but consideration should be given on a case by case basis to notifying the external auditors immediately that the fraud comes to light.

Cases of fraud in bodies sponsored by the Scottish Government should also be notified to the sponsor unit.

 

Page updated: August 2026

Back to top