RSS Amplifier

The Integrity Gap · Jul 16, 2026

Why don't leaders want to save money?

0
Sign in to vote or save

Rupert Evill · The Integrity Gap

Earlier this year, I asked why most firms (growth-stage and beyond) have bribery, corruption, and sometimes money laundering frameworks, but none for other types of fraud we know to be more common (see chart from the ACCA combating fraud survey below).

A head of compliance at a large multinational sent a direct message saying, “because unlike money-laundering, sanctions breaches or corruption, there are no laws explicitly prohibiting the occurrence of fraud and sanctioning those businesses that allow it to happen.”

Picking on the UK, the Bribery Act came into force nearly 15 years ago. Since then, we’ve had ~6 prosecutions and a couple of deferred prosecution agreements. Being generous, let’s round that up to 10 prosecutions. Some of those 10 were fairly modest Ltd companies. There are 2.1 million actively trading Ltd companies, and about 40,000 turn over £5m or more.

10/15(yrs) = 0.7 prosecutions per annum.

0.7/40,000 = 0.0000175

Or... 0.00175%

Yes, there are other, more aggressively prosecuted pieces of legislation, but you get the point.

And I’m picking on bribery because most of those prosecutions were illegal payments to get “undue benefit” (i.e., to win).

So, what I’m being told is that a business leader sees the cost-benefit in investing in an anti-bribery system where the upside is potentially winning and the downside of getting caught and prosecuted is a fraction of a per cent...?

I’m not saying that is the calculation, and I am deliberately inferring nefariousness to promote discussion and to make a point.

The cost of fraud, at the median point, for a business with <100 people is now $126,000 (greater than the median loss for 10,000+ organisations). The average loss per case in the same ACFE study was just under $1.5m.

So, business leaders see ROI in preventing bribery, even when prosecution is remote, but no point in preventing fraud when an average mid-cap might lose money with the following probability:

  • According to the BDO Fraud Survey (which tracks UK companies with 200+ employees), 42% of mid-sized businesses fell victim to fraud in 2024. This was a decrease from 60% in 2023 and a peak of over 68% in 2022 during the height of the cost-of-living crisis.

  • The 24-Month Trend: PwC’s UK Economic Crime Survey found that 64% of UK businesses experienced some form of fraud, corruption, or economic crime within any given two-year window.

  • The Size Vulnerability: The UK Government’s Economic Crime Survey notes that while the baseline annual fraud rate across all UK businesses is 27%, the rate jumps dramatically for medium and large corporations. Their larger supply chains, higher transaction volumes, and decentralised workforces create far more targets.

So, the problem isn’t probability. Bribery (or money laundering) prosecutions can’t be driving the behaviour, at least not rationally, or alone.

I think it’s because we do a terrible job of articulating and explaining fraud. What it is, where it occurs, why, how, and when. We then do an equally poor job of building fraud prevention measures that don’t drive everyone up the wall.

In this context, fraud prevention has to move in the direction of cybersecurity - security-by-design. Building the prevention, detection, and response capabilities into existing processes. I can’t address that in its entirety in a post. Still, I will direct you to the three tools below that we drafted for the Fraud Advisory Panel and its sister organisation, the Business Fraud Alliance.

Maybe in a future edition, I might run a Fraud Prevention + AI 101, showing how these PDFs could be turned into prompt packs to integrate into existing processes (e.g., reconciliations, vendor master data, inventory management, accounting, etc.). Would that be useful?

For now, click on the image below, find your sector, download a free risk assessment, have a read, and let me know what you think.

No posts

Read the original on ethicsinsight.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.