RSS Amplifier

The Integrity Gap · Aug 20, 2026

Soggy Cornflakes, AI Bilge and Serious Fraud

0
Sign in to vote or save

Rupert Evill · The Integrity Gap

Welcome to August’s long-form edition of The Integrity Gap. For new subscribers, the general format is:

  • What We’re Seeing - 3 trends or emerging risks

  • Intel - 1 case study

  • Tools & Resources - 1 practical framework or idea

  • What’s Next - forward-looking insight

  1. In perhaps the least surprising study since “A Study of the Effects of Water Content on the Compaction Behaviour of Breakfast Cereal Flakes [why do cornflakes go soggy when milk is added],” we learn: “People Who Love Corporate BS Are Bad at Their Jobs,” courtesy of Cornell Research. I’m sure you will be falling off your seat as you read this. If you would like a visual representation of this phenomenon, circle back to WankerNomics.

  2. AI compliance software bilge. In a recent newsletter, I saw an advert for a webinar promising to connect various LLMs “directly to your compliance program” to “catch risks, fix gaps, and stay audit-ready.” I then looked at the features list on the software firm's website and sighed. It looks at your policy and procedure framework, asks you 100-200 questions and spits out a score. So, they’re charging a fortune for a prompt pack with a simple markdown document that interrogates your data against a boilerplate list. Real risk lives in the gaps between context, controls, and culture (how you behave). There is a profound difference between adaptive software and generalised prompt packs.

  3. Beware AI detection: In a letter to The Economist, Brendan Lyons from Dublin noted, “I can confirm that software designed to detect AI-generated text is indeed “black-box algorithms that can give false positives'” (“Paper trails”, 1 August). I ran some texts through an AI detector. Samuel Beckett’s Krapp’s Last Tape and Happy Days were judged likely to be 86% and 84% AI-generated. The Sermon on the Mount was thought to be 100% AI-generated.”

At the start of a due diligence process or an investigation, what amount (or type) of information would be enough to make a decision?

It’s hard to imagine. But it’s essential. Without some idea of how much information is required to make a decision, we can waste a lot of time and money. Occasionally, we get lucky, as there is a predefined threshold.

For example, each year I take on a small handful of investigative projects. One such recent case involved tracing people across continents in relation to the estate of someone who died without an obvious heir. The law (in the country of the deceased) helps us define the boundaries of the investigation, as it stipulates how far along the branches and roots of the family tree you can travel to prove a relationship.

In other investigations and diligence projects, it can be trickier to know where to draw the line. For example, we might agree in investment diligence that we must ensure the company acquires land, licenses, concessions, and clients in a professional manner. Especially if these things are crucial to the ongoing viability or could pose major reputational (and legal) liability. But we may allow more latitude around how they select the contractors to develop on that land, recognising that proper diligence and appropriate monitoring sit on a continuum (risk-based). In an investigation, civil, criminal, or company contracts may define evidential thresholds that help us decide how much information is sufficient.

For everything in between, take 10 minutes to sit in silence (big ask, I know). No phone, no distractions. Imagine the worst-case scenarios. The company you invest in turns out to be a rolling nightmare of fraud, chaos, headaches, and deception. The investigation misses crucial findings enabling further, larger wrongdoing, whistleblower retaliation, and reputational carnage.

Now ask, what amount of digging would have been enough to move this from “I should have seen this coming” to “We took robust and reasonable measures to prevent...” We can’t stop humans from being human (pressure and our internal rationalisations routinely make us do things we know we shouldn’t). But we can define what is defensible, enough.

I’ve written previously about fraud becoming a collaborative service line for organised criminal groups (OCGs), having seen it firsthand in Cambodia, Laos, and Myanmar in the early 2010s (the precursor to the human-trafficking ‘towns’ we now read about). At that stage, some of Africa’s more prominent OCGs (particularly Nigerian 419 scammers) were laundering cash through SE Asia and learning from more established OCGs (Russian Bratva, North Korean Lazarus precursors, Italians, Yakuza, Triads, etc.).

So, it is depressingly predictable that this cancer would spread and metastasise across Africa. INTERPOL’s African Cyberthreat Assessment Report 2026, covering January to December 2025 across 26 member countries, found that cybercrime losses alone have more than doubled since 2024, from $192 million to $484 million. This will be a drop in the ocean, as many frauds go unreported, unseen, and extend beyond cybercrime. For example, in a recent research project on the circular economy, we found endemic and systemic OCG fraud across a range of activities, from copper wiring thefts from infrastructure (then ‘recycled’ and laundered as legitimate e-waste) to trade-based money laundering in transnational waste shipments.

To combat a scourge (OCG-backed fraud) which is now the world’s third-largest economy, we need to do a few things we’ve been abysmal at:

  1. Ownership: Move fraud from being everybody’s and nobody’s problem to one that is owned.

  2. Risk assessment: View fraud as we do other asymmetric risks (like terrorism), considering threat actor intent and capability, and our likely vulnerability. Whole industries have pivoted to stop liquids on planes after ONE shoe-bomb plot, yet fraud is still treated as something nebulous — we know who the baddies are and what they want.

  3. Monitoring: AI tech solutions and plug-ins for monitoring fraud patterns are available and can integrate with existing processes. We’ve proven this with Ranulph™, and on numerous projects (see the risk assessment tools we developed for the Business Fraud Alliance here).

Think of all the good that could be done if more money stayed in the hands of the right people and away from people whose other ‘revenue streams’ mainly centre on death, exploitation, addiction, war, rape, and suffering. Time to fcuking wake up!

A few weeks back, I wrote about the ethics of getting a cut for introducing someone. It seems to have struck a chord and has since sparked a few conversations.

So I’ve been trying to build a framework for the murky space between a favour, a referral, a commission and a joint venture. The objective is to balance ethics with opportunity (your introduction may create). So, how’s this for a first draft?

So, for us, this is how it’s starting to look in practice:

  • A referral compensates origination (usually a one-off, unless it creates an ongoing engagement, such as a master services agreement).

  • A commission normally compensates for a sale or transaction (it should ‘decay/diminish’ over time).

  • A revenue share makes more sense when both parties continue creating value.

  • A joint venture should compensate for contribution, risk, IP, delivery, and perhaps capital.

“You can get the answer without effort, but you can’t get the understanding.”
Shane Parrish

If any of this lands, let’s talk.

No posts

Read the original on ethicsinsight.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.