Fraud
Expanding Role of the ISO
Last Updated: March 14, 2026Fraud is not a component of the GRC framework. It has its own legal definitions, its own professional disciplines, its own specialist investigators, and its...
Fraud Risk Assessment
Last Updated: March 14, 2026Fraud risk assessment is the systematic process through which the organisation identifies, analyses, and prioritises the specific fraud risks it faces across its operations, assets,...
Internal Fraud
Last Updated: March 14, 2026The Insider Threat Dimension Internal fraud represents a qualitatively different governance challenge from the external fraud threats that the organisation’s perimeter defences, email security controls,...
External Fraud
Last Updated: March 14, 2026Threats, Vectors, and the ISO’s Defensive Role External fraud originates from parties outside the organisation’s workforce whose objective is to exploit the organisation’s processes, systems,...
Detecting Fraud
Last Updated: March 14, 2026Fraud detection is the discipline through which the organisation identifies fraudulent activity that prevention controls have not stopped, limiting the financial, operational, and reputational damage...
Managing Fraud Risk
Last Updated: March 14, 2026The governance of fraud risk has undergone a fundamental shift in the expectations that boards, regulators, and investors place on organisations. Fraud was historically managed...
Cultivating an Anti-Fraud Culture
Last Updated: March 14, 2026The preceding sections of this publication’s fraud domain have addressed the identification of fraud risks, the detection of fraudulent activity, and the strategic governance of...
