Purpose - Attorney-General`s Department

advertisement
Commonwealth Fraud Control Policy
Purpose
i.
The Commonwealth Fraud Control Policy (the Policy) has been developed to support the
accountable authorities of non-corporate Commonwealth entities (entities) to effectively
discharge their responsibilities under the Public Governance, Performance and Accountability
Act 2013 (PGPA Act) and section 10 of the Public Governance, Performance and Accountability
Rule 2014 (the fraud rule). Under section 21 of the PGPA Act, the accountable authority of a
non-corporate Commonwealth entity must govern the entity in a way that is not inconsistent
with the policies of the Australian Government.
ii.
The Policy sets out the key procedural requirements which the Government views as necessary
for accountable authorities to establish and maintain an appropriate system of fraud control
for their entity. Consistent with the fraud rule, the objectives of the requirements are to:
 protect public resources, including money, information and property, and
 protect the integrity and good reputation of entities and the Commonwealth.
Scope
iii.
Consistent with the Commonwealth Risk Management Policy corporate Commonwealth
entities are not required to comply with this Policy, but should review and align their fraud
control frameworks and systems with this Policy as a matter of good practice.
iv.
Non-corporate Commonwealth entities must comply with this Policy by virtue of section 21 of
the PGPA Act.
v.
Non-corporate Commonwealth entities must ensure that their fraud control arrangements
are developed in the context of the entity’s overarching risk management framework as
described in the Commonwealth Risk Management Policy.
vi.
This Policy commences immediately after the commencement of section 10 of the PGPA Act
rule or 1 July 2014, whichever is the later.
Introduction
vii.
The fraud rule sets out the key principles of fraud control which all accountable authorities
must comply, but allow entities flexibility to develop measures which are adapted to the risks
of that entity’s own arrangements.
viii.
The procedural requirements in this Policy supplement the fraud rule and aim to ensure key
elements of fraud control are maintained by entities. The procedures relate to fraud control
activities in particularly sensitive areas, where there is a high risk of significant impact to the
entity if they are not appropriately maintained. The procedures are also intended to ensure
the necessary level of accountability.
ix.
As with the fraud rule, additional information on implementing the requirements in this Policy
are set out in guidance issued by the Minister for Justice – Resource Management Guide No
201 Preventing, detecting and dealing with fraud (fraud guidance).
Commonwealth Fraud Control Policy
Page 1 of 4
Commonwealth Fraud Control Policy
Commonwealth fraud control procedures
x.
For the purposes of the Policy, the fraud rule and fraud guidance, fraud is defined as
‘dishonestly obtaining a benefit or causing a loss by deception or other means’. This definition
is based on the fraudulent conduct offences under part 7.3 of the Criminal Code Act 1995, in
addition to other relevant offences under chapter 7 of the Criminal Code.
xi.
In addition to the requirements set out in the fraud rule, the accountable authority must
ensure that the entity meets the following procedural requirements:
Prevention and training
1.
Entities must document their instructions and supporting procedures that assist officials to
deal with fraud.
2.
All officials and contractors must take into account the need to prevent and detect fraud as
part of their normal responsibilities.
3.
Entities must ensure that officials who are primarily engaged in investigating fraud as a
minimum meet the required fraud control competency requirements set out in the Australian
Government Investigations Standards (AGIS) within 12 months of being engaged in
investigating fraud.
4.
Entities must ensure officials primarily engaged in fraud control activities possess or attain
relevant qualifications or training to effectively carry out their duties within 12 months of
being engaged in fraud control activities. Relevant qualifications include a Certificate IV in
Government (Fraud Control) or equivalent for officials primarily engaged in fraud risk
assessment, and a Diploma of Government (Fraud Control) or equivalent for officials primarily
engaged in the coordination and management of fraud control activities.
Outsourcing
5.
Outsourcing does not remove the responsibility of the accountable authority to manage fraud
risk. However, when an entity provides third-party services for another entity, the entity
delivering the service retains responsibility for meeting the first entity’s obligations under this
Policy and the fraud rule.
Investigations
6.
Entities must take into consideration the requirements of the AGIS when developing systems
and processes for the detection and investigation of fraud.
7.
Entities must maintain appropriately documented procedures setting out criteria for making
decisions at critical stages in the management of a suspected fraud incident. The procedures
must be consistent with the Policy and in accordance with any relevant requirements under
the AGIS.
Commonwealth Fraud Control Policy
Page 2 of 4
Commonwealth Fraud Control Policy
8.
Entities must appropriately document decisions to use civil, administrative or disciplinary
procedures or to take no further action in relation to a suspected fraud incident.
9.
An entity is responsible for investigating instances of fraud or suspected fraud against it,
including investigating disciplinary matters, unless the matter is referred to and accepted by
the Australian Federal Police or another law enforcement agency.
10.
Where a law enforcement agency declines a referral, entities must resolve the matter in
accordance with internal and external requirements such as the AGIS and relevant entity
specific criteria.
11.
The AFP has the primary law enforcement responsibility for investigating serious or complex
fraud against the Commonwealth. Entities must refer all instances of potential serious or
complex fraud offences to the AFP in accordance with the AGIS and AFP referral process,
except in the following circumstances:
a) entities that have the capacity and the appropriate skills and resources needed to
investigate potential criminal matters and meet the requirements of the Commonwealth
Director of Public Prosecutions (CDPP) in preparing briefs of evidence and the AGIS for
gathering evidence, or
b) where legislation sets out specific alternative arrangements.
12.
Investigations must be carried out by appropriately qualified personnel as set out in
paragraph 3. If external investigators are engaged, they must as a minimum have the required
investigations competency requirements set out in the AGIS.
13.
Entities must have in place investigation processes and procedures that are consistent with the
AGIS. Entities must also comply with the Prosecution Policy of the Commonwealth.
14.
Entities must take all reasonable measures to recover financial losses caused by illegal activity
through proceeds of crime and civil recovery processes or administrative remedies.
15.
Where an investigation discloses potential criminal activity involving another entity’s activities
or programs, the investigating entity must report the matter to that entity in accordance with
the Privacy Act 1988 and the Australian Privacy Principles.
Reporting
16.
Entities must have procedures in place to manage information gathered about fraud against
the entity.
Australian Institute of Criminology report on fraud against the Commonwealth
17.
All entities must collect information on fraud and provide it to the Australian Institute of
Criminology (AIC), by 30 September each year to facilitate production of an AIC annual report
on fraud against the Commonwealth and fraud control arrangements. The AIC must provide
this annual report to AGD within six months of receiving the information collected under
paragraphs 17, 18 and 19.
Commonwealth Fraud Control Policy
Page 3 of 4
Commonwealth Fraud Control Policy
18.
In addition to providing data under paragraph 17 to the AIC, the AFP is to provide annual
information to the AIC on all fraud incidents against the Commonwealth referred to, accepted
or declined by, the AFP during the previous financial year. The precise data items will be
agreed between the AFP and the AIC.
19.
In addition to providing data under paragraph 17 to the AIC, the CDPP is to provide annual
information to the AIC on all fraud incidents handled by the CDPP during the previous financial
year. The precise data items will be agreed between the CDPP and the AIC.
Attorney-General’s Department report on compliance
20.
The AIC must provide the relevant information it collects under paragraphs 17, 18 and 19
within six months of receiving it to the Attorney-General’s Department (AGD) to facilitate
production of an AGD annual report on whole-of-government compliance with the
requirements of the fraud rule and this Policy.
Reporting to Ministers or Presiding Officers
21.
Accountable authorities must provide a report annually to their Minister or Presiding Officers,
which includes:
 fraud initiatives undertaken by the entity in the reporting period, including an evaluation of
their impact on fraud prevention, detection and response
 planned fraud initiatives yet to be implemented
 information regarding significant fraud risks for the entity, and
 significant fraud incidents which occurred during the reporting period.
Glossary of terms
Accountable authority – The person or group of persons who has responsibility for, and control
over, a Commonwealth entity’s operations as set out under section 12 of the PGPA Act.
Commonwealth entity – A department of state, a parliamentary department, a listed entity or a
body corporate established by a law of the Commonwealth.
Commonwealth official (official) – An individual who is in, or forms part of, the entity as set out
under section 13 of the PGPA Act.
Corporate Commonwealth entity – A Commonwealth entity that is a body corporate and legally
separate from the Commonwealth.
Non-corporate Commonwealth entity – A Commonwealth entity that is not a body corporate and
legally part of the Commonwealth.
Serious and complex fraud – Fraud which due to its size or nature is too complex for most entities
to investigate (further information serious and complex fraud can be found in the fraud guidance).
Commonwealth Fraud Control Policy
Page 4 of 4
Download