Transcript
Speaker: Welcome the latest episode of the Exchange Podcast. My name is Bethan Smith and I'm part of the Good Practice Exchange team here at Audit Wales and I'm really pleased be hosting today's podcast. Hopefully you've had chance to listen to our first episode, which was a conversation with the Auditor General for Wales, Adrian Crompton.
Speaker: If you haven't, I'd really recommend you go back and have listen. So, on to today's episode. Now, whilst there's lots of conversations around public finances that often focus on spending cuts and rising taxes, today we're going to be talking about fraud and error.
Speaker: Fraud continues to be a huge challenge for public services and organisations more broadly across Wales. The Public Sector Fraud Authority estimates there's around £39 billion pounds of taxpayers' money subject to fraud and error every year.
Speaker: Today I'll be chatting to a brilliant panel of speakers, all with expertise in this field. We'll be discussing some of the fraud risks and challenges, we'll looking at how public services are responding, the role of leaders and how effective collaboration plays its part. We'll also be looking at opportunities and how we should be preparing for the future.
Speaker: So let's introduce you to the panel. Good afternoon, I'm Steve Tooby. I'm a former senior police officer in South Wales Police. I've been headed various departments from the CID for surveillance team, economic crime unit and the Wales regional asset recovery team.
Speaker: I've investigated every day crimes to serious and organised crimes. After retiring from the police, I was a lead investigator for the illegal many lending unit targeting loan sharks in Wales and ensuring victims were supported back into financial inclusion.
Speaker: I'm currently head account of fraud for the Welsh Government and have been there for 15 years. My role is primarily to prevent and investigate fraud against the Welsh Government ah protecting public money.
Speaker: Although this year I've been heavily committed on a new piece of fraud legislation with the UK Cabinet Office. It's called the Public Authorities Fraud Error and Recovery Bill and ensuring the parts that impact upon devolved matters are provided within the Senate's consent. Good afternoon, my name is Graham Dainty.
Speaker: I'm the head of the NHS Wales Counter Fraud Services. That consists of seven persons in the national team that investigate large scale complex cases across NHS Wales.
Speaker: And we also provide support and guidance to a network of 24 local counter fraud specialists. who were employed by based at individual health bodies in Wales, they tended to have a more proactive role and also investigate the smaller scale cases across Wales.
Speaker: Prior to taking up this role 24 years ago, um i previously worked in the Hong Kong Police, predominantly in the Commercial Crime Unit of the Hong Kong Police, before I came back to take on this role.
Speaker: Hello, good afternoon. My name is Steve Benson-Davison. um I'm also a retired police officer. I was a senior detective and worked within the COVID world and murder investigation teams for many years. I now work as a regional fraud prevent officer within the regional organized crime unit.
Speaker: Good afternoon, my name is Rachel Costick. I'm a manager at the Regional Economic Crime Unit, which is part of Tarian. We cover the three Welsh forces of David Powys, Gwent and South Wales Police.
Speaker: And we focus on the pursue element of financial crime, investigating fraud and money laundering um and recovering the proceeds of crime. Thanks, Rachel. So we'll kick things off straight away and I'm going to come to you Graham first. So what are the biggest fraud risks currently facing the public sector and organisations more generally in Wales?
Speaker: From NHS perspective, we've had several procurement cases where people have set up their own companies and then allocated the NHS work to their own companies.
Speaker: Obviously, the senior managers weren't aware of this arrangement. The work has been completed to a very poor standard and therefore the issues were identified and investigated.
Speaker: Several cases have gone to the Crown Court and the individuals have actually been sentenced to considerable times in prison. We've also then followed the civil recovery route to get the money back using the Proces of Crime Act powers that we have under the Proces of Crime Act 2002 and where suitable we also pursue disciplinary action So it's called triple tracking approach or parallel sanctions and whatever appropriate sanctions are available to us, we always seek all all three routes if possible.
Speaker: um Staff fraud, i don't think that's any different really to any other big organisation. It's important to emphasize the very small minority of NHS staff who are committing fraud.
Speaker: The vast majority are honest, hardworking individuals and it's persuading perhaps the honest majority to report their colleagues who are committing that fraud the examples i give you there you've got people phoning in on a weekend feigning sickness and then they can work privately obviously having two salaries coming in on weekend you could double pay on a weekend There's obvious examples like that, expenses, for fraud, etc. That's no different to any other big organisation.
Speaker: um The contractors, I do the things as well. By contractors, I mean your dentists, your pharmacists, your GPs and your opticians. We often get frauds referred to us there where previously we have had to investigate pharmacists, GP practices, and lately we've had several cases in the Crown Court where GP practice managers have had control of the finances of the GP practice and they've taken advantage of the lack of scrutiny.
Speaker: Perhaps the checks and balances weren't as tight during the COVID period and now cases are coming to light on the few years after COVID then. One example I'll give you is a GP practice manager in the Betolburt area was recently convicted of fraud valid 320,000 and that only came to light because a GP found a fake invoice for a locum GP on the photocopying machine and then started doing some inquiries and then referred the case to us for investigation.
Speaker: So broadly that's what we're dealing with on a day-to-day basis. And I'll look to Steve now in your role within the Tarion unit. Are you seeing similar examples across private sector organisations as well? um and I think what Graham's alluding to there is a lot of fraud which is um what I would say internal type fraud where it's fraud being committed against the NHS by people who are engaging with them in a business perspective. But we've also got lots of frauds that we see where um external fraudsters will look to um take money, steal money from lots of different businesses. so
Speaker: um You know, with the cyber risk, you know, most businesses now will have a cyber threat where perhaps their cyber security has been breached by the fraudsters and data is stolen.
Speaker: And then the criminal gangs who were based, you know, 70% of the time based outside of the UK will use that information to defraud those companies and others. So for example we see lots where a company will have their cyber security breached through phishing email where a staff member may have clicked on an email, downloaded some sort of um some virus into their systems that allowed the criminals to gain access.
Speaker: And once they gain access to the the systems, they can see purchase orders and invoices. They'll understand who that company is doing business with. They'll replicate those those receipts, those those orders, place them themselves, ah purporting to be the the company that's been hacked.
Speaker: um And of course, the the goods that are then um ah provided are stolen by the fraudsters. And the first the company that's been hacked knows about it is when they get a a purchase order, a bill, basically, a month later, saying and this is for the the goods that you ordered, which, of course, they haven't. So we're seeing lots and lots. And that is one of the major issues that companies are facing, simply because the cybersecurity and staff awareness isn't what what it should be.
Speaker: Steve, I guess from a Welsh government perspective, then, what are the kind of things you're seeing? Very similar to what Graham was mentioning. I mean, from identity fraud through to particularly false documentation, that's so easy to create now.
Speaker: um I mean, it always was with IT, but now with AI, it's got even better, if you like. um Conflicts of interest, as as Graham alluded, with the the setup of ghost companies,
Speaker: or companies just with a sole interest in one particular trade ah to obtain money either from the NHS or the Welsh Government come to that. um Our main risks around grants and procurement, which should be no surprise really, but now moving forward with AI digitalisation unless we keep up and keep track because, let's face it, fraudsters are very innovative.
Speaker: And we've got to be as innovative and proactive more than ever. It's much easier to prevent fraud than investigate it long-running, costly investigation. no Absolutely. And we'll then we'll cover AI a little bit later on as well. but um I guess the next question I was going to ask is around and how organisations balance fraud prevention with service delivery then and I'll come to you Graham again from an NHS perspective you know the NHS I guess under a lot of pressure to deliver how then do you kind of shift resources to be able to look at and manage manage fraud as well
Speaker: Previous studies have indicated that the and NHS lose on average about 6% of its budget to fraud. That's a big chunk of the NHS budget which should be used for patient care.
Speaker: I think 99% of the population would agree with that comment. um It's basically raising staff awareness of fraud risks and encouraging staff to report their concerns.
Speaker: We have an e-learning presentation which all staff are encouraged to complete on a three-yearly basis, and that's updated on a 12-month basis, just the data's updated, et cetera.
Speaker: And then we also do presentations directly to staff. So it's finding that balance between a reactive investigative resource, which we do have, ah where we investigate cases and take them to the Crown Court or the Magistries Court, with whichever is appropriate,
Speaker: But there's also encouraging staff to report their concerns. You may find that staff have gone to the line managers and that the line manager is reluctant to report the staff's concern because it may reflect badly on the line manager.
Speaker: Not directly, in that the line manager isn't implicated in the fraud. but the checks and balances that he or she should have done haven't been conducted, and therefore they try and bury that referral rather than investigating or referring it to the appropriate people.
Speaker: So we have a fraud and corruption reporting line. We also have an online reporting tool, and we encourage people to report any concerns that they may have. Yes, thanks, Graeme. I think it's known what to look out for, as you say, and those kind of reminders and prompts for staff.
Speaker: Steve, I'll look to you on this one now. How are you seeing organisations balancing that fraud all prevention with service delivery? You know, there is a balance there. um
Speaker: It's interesting Graeme said there about the 6% of um the budget for NHS is vulnerable to fraudulent activity.
Speaker: um So it just goes to show just how important it is that businesses, industry, companies, no matter how big or small, are aware of the risk and the threat, and that's both internal and external. um So, and I think that's the challenge, is that we're seeing with businesses that, you know, always the focus is on getting the next contract and, you know, paying the wages of staff.
Speaker: But what we've got to realise now in this ever-increasing digital age is the risk that comes from um the threat from fraud and cyber attacks. And... and It's not just big businesses. you know We've seen lots of cyber attacks against major businesses recently. Marks and Spencer's the co-opters to name two. But it's the small businesses that are also very, very, very vulnerable. And the reason for that is that one, the cybersecurity isn't as secure.
Speaker: um So it's not as difficult to breach the cyber security of small company, for example, solicitors, estate agents, dentists, you know veterinary practices. And once their cyber security been breached, then the the the criminal gangs have an opportunity to either steal data or... um lock up their systems that they can't access them unless they pay a ransom. So you know staff and managers, leaders need to be aware and to train and to raise awareness of their staff of what the dangers are. So for example not clicking on the links on emails, not opening suspicious messages which are coming through. you know making sure that before you send money to different accounts where perhaps you know you've had a message to say that a bank account number has been changed, that you verify and check.
Speaker: And the government's strategy now is stop think fraud. And that is relevant for you know personal individuals in their business, but also in the working environment. um So, you know, it's key that there is a balance between the working practices but also being aware of the risk of where you can lose an awful lot of money or even for businesses to be completely taken down by a cyber attack.
Speaker: Sticking on the detection and prevention of fraud then, as we've said, lots of these issues are being seen right across the board. It's not just a health issue, it's not just a local government issue, it's happening everywhere. So how can organisations collaborate more effectively to prevent fraud?
Speaker: I think from a Welsh Government point of view, when we're investigating frauds or trying to prevent it, um we've got to be forthright and we operate within the bounds of the law.
Speaker: So whenever I'm into an investigation and it might be another public body or private body, I normally do a data sharing agreement which fits under the ah UK GDPR rules and data protection rules.
Speaker: um There are other statutory powers where you can share information, the Serious Crime Act, Digital Economy Act and the new legislation that I alluded to in my introduction to Public Authorities Fraud Error and Recovery Bill which should receive Royal Assent before the end of the year.
Speaker: um But date to sharing agreements are key um for that collaboration to understand the roles and responsibilities The same as sharing information with with other groups.
Speaker: Graham and I are members of the Wales Fraud Forum, where there's a lot of networking goes on. We have three working groups a year, primarily for topical subjects, but again networking, and we have an annual fraud conference every year.
Speaker: ah which Steve spoke at this year. So the the collaboration is there. There's also another, there are eight what we call gain groups around the yeah UK, but we've our own Wales one, Government Agency Intelligent Network, which all regulators, enforcement authorities, share intelligence for want of a ah better phrase, to understand what is current, what is causing them sleepless nights, if you like, and how we can all help um
Speaker: to protect an organisation or protect the public from fraud. And occasionally you will feed information in and you'll find another organisation, maybe looking at the same organised crime group or same individual. So collaboration is key this day and age because you don't know what you don't know.
Speaker: For anyone listening now that might be interested in some of those networks you mentioned and the forums, how would they get involved with that? The Wales Fraud Forum is open for membership for anyone. We've our own website.
Speaker: We put alerts out on that occasionally on frauds. um So you can always come along to our meetings. They're advertised regularly if you've a particular interest in a working group. Sometimes they're online, sometimes they're they're in sort of face-to-face.
Speaker: and you can also suggest areas where we may have but missed in relation to fraud prevention investigation and the like to be honest i mean we've quite a big membership within wales and it's it's well attended every year our annual conference and it's a good way if you're involved in fraud or trying to prevent it, to speak with others, to gain best practice and learn lessons.
Speaker: Steve mentioned the GAIN, which is the Government Agency Intelligence Network, which um there's a number of individuals who perform that role across government agencies. So within the regional crime unit, we have a Gain coordinator. We also have an embedded staff from HMRC and other agencies, Borders and Immigration is another, ah working within our unit. So that collaborative approach is there. The Gain coordinator can reach out to 26 other government agencies across Wales. So the ability to link in with other agencies is there through those individuals. As Steve mentioned, the legislation is in place to allow for the sharing of information So, you know, a collaborative approach um is there for, you know, if if if different agencies want to get together to share best practice, to share training and and awareness raising, then, you know, the opportunities are there.
Speaker: I think if I'm just coming on the back of that, I think a lot of agencies are frightened, for want of a better word, of sometimes sharing their information in fear of the legislation.
Speaker: But if the legislation is understood and used correctly, It's all can do legislation as opposed to can't do. And if you're unsure, speak to some experts in it.
Speaker: You've got the ICO office as well. You can also gain advice from. They've got an advice line. So go in with a glass half full thinking that you can do it until someone tells you you can't.
Speaker: And what we'll do, and all those networks and everything that have been mentioned, we'll put alongside on our website just so anyone listening to this can go away and have a look at um how they can get involved in that.
Speaker: From an NHS perspective, we were collaborative with several bodies, including the National Crime Agency on the Process of Crime Act actions that we take. um We restrain the money prior to an investigation.
Speaker: Once we secure the criminal conviction in the court, we then seek to recover the funds. On my team, there are three accredited financial investigators and three financial intelligence officers.
Speaker: So every case that we investigate is considered for appropriate action under the Process of Crime Act. um Further on to that, we also work closely with the local police forces in Wales, the police services in Wales. We've got very good contacts with the economic crime units and we don't have any powers of arrest or search.
Speaker: So we develop the case, we then take the case to the economic crime units usually. They then apply for the search warrants. We are named on the search warrants, so we retain conduct of the investigations.
Speaker: So, in answer to your question, we work very closely with several investigative agencies throughout Wales and elsewhere. Just on that point then around the Proceeds of Crime Act, Rachel, what happens with the proceeds of fraud when someone has been convicted?
Speaker: As we mentioned, we use we we use the Proceeds of Crime Act and we look at confiscation, asset denial, um civil recovery, um compensation if there are victims involved. So we always look to get the proceeds of crime back to the victim in the first instance. But if not, we recover the monies then um for confiscation, we calculate the the benefit of their criminality. What we found is, you know, people don't mind serving time in prison, um but what really hurts them is having their money, their assets, you know, the nice houses, cars, and things that they've earned from their criminality taken off them. and We find that is ah is a lot more impactful than, um you know, your prison time. um
Speaker: So, yeah, we we we always look to calculate what they've earned from their criminality and recover that money. So, Steve, we sort of briefly touched on this earlier around ai I guess the next question we had was what the risks are.
Speaker: You know, AI it seems to be everywhere at the moment. But what are some of those risks that organisations kind of need to be aware of or look out for? I think the risks with AI is believing everything that comes out of it.
Speaker: um You know, we can all use AI this day and age, but then when you read through it, if you've interpreted a question into it the wrong way, you can get some false data out. So all that AI needs to be checked, but certainly from fraud attacks, being able to produce documentation like it's never been produced accurately, believable, it's getting difficult to spot false invoices, false false receipts, or even false bank statements, which used to be the catch-all if you were looking to investigate a case. to A bank statement very often tells you a story from when purchases were made.
Speaker: If they're false now, they can read any story they like. So we certainly in the public sector, and I do say the private sector, need analytical tools now to combat fraud.
Speaker: We need to keep pace. um We in the public sector probably, and i'm not just referring to the Welsh government, have got IT systems that don't always talk to each other.
Speaker: um we're We're trying to cater that for that at the moment and update ourselves as quickly and as responsibly as we can. But you need to get it right. IT is moving so quickly and AI is moving so quickly.
Speaker: If you take a couple of years to do it, you could be outdated very, very quickly. So you need the expertise there, and it's certainly within Welsh Government, that's what we're doing at present.
Speaker: But I dare say other organisations, local authorities, etc, need to be doing the same. And I know it's happening on a national basis. um People trying to keep pace with the fraudsters, really. that that That's the main risk.
Speaker: um You've got... Image recognition. We've seen that not just for the public sector, but certainly from dignitaries around the world providing false information, etc.
Speaker: You don't know what to believe this day and age. So you need the power of AI to combat it as well. And you need the power of AI to be save resources and spot more fraudulent behavior.
Speaker: I mean, it's that that intelligent that can spot behavioral fraud before a human can do it. It'll spurt out the information in abundance. Hopefully it will save from creating the false positives that so much data analytics used to do.
Speaker: um So you need the resources in place to deal with what comes out of the a AI analytics. um So it's a fast-moving world in fraud at the moment. But, you know, a fraud team this day and age, when I first started, you'd need a good fraud investigator manager, skilled up in the various roles.
Speaker: Now you need data analysts, data technicians, forensic accountants, auditors, etc. to complete your fully-fledged fraud team. Yeah, no, I'd agree. i am It's suggested that 50% of fraud um now is AI-enabled, um but that's likely to be underreported because, like Steve said, it's difficult to even identify in the first place. So, you know, the chances are we've missed so much because we haven't even recognised that it's there. We, Atari, and we've um kind of recognized AI as an emerging trend and we've invested in an AI coordinator. um So the is it's the first um the first one in throughout all the Rockies in the UK. And he's he's working on raising awareness around AI, going out, giving presentations to people, linking up um and networking around you know what people are doing around AI, how they're using it for good and bad, um
Speaker: And as you said, it's so difficult to detect. We've seen some of the like like bank statements, receipts that he's produced just to show us how it works. And you you wouldn't you wouldn't tell the difference.
Speaker: It's interesting you mentioned about the skills that are now required of the workforce going forward and how much that has had to adapt and change over the years. And it's really interesting to hear about your AI coordinator now in post, Rachel. as you say, 50% of cases is such a huge number. I guess where there's challenges with AI as it develops, there's also lots of opportunities, Steve. You knowi um can conceive ah you know, save lot of work which which used to be done
Speaker: you know manually. it can It can find information, pull information out so much quicker. So, you know, there's lots of benefits to AI. Steve alluded to the fact that it's not always 100% reliable. You've got to you know check the facts that come out of it.
Speaker: But, you know, it's certainly here to stay and it's going to get better. It's going to get more reliable. And we've seen that certainly in the fraud world with, um you know, the technology allowing for the graphics and grammar on fraudulent emails and um videos.
Speaker: um and presentations are becoming increasingly difficult to spot. So whereas previously, you know, 10, 15 years ago, you'd have had a fraudulent email, which is asking you to do something, and the grammar and the graphics, you looked at it and immediately thought that doesn't look right, that doesn't ring true to me.
Speaker: But AI now has just totally cut through that. So it's very difficult to spot a fraudulent communication. And so what we say now is any communication you get, treat it as information, but you've got to double check what where that's come from and who it's from. So if it's something that, you know, Amazon or or something that you've got an app for or from the bank, you delete the message and you go into the actual app in order to check if the message is there. You've, you know, because ai is is that good. um It's been used a lot in romance fraud, where people are convinced that they're actually speaking on a daily basis on on a webcam to a famous celebrity.
Speaker: Harrison Ford, for example, is is one that the fraudsters commonly use to encourage people to become a member of their membership club and pay extra money to have a daily face-to-face online, which is all completely deep-faked individuals. you know So that's what AI is is developing for the fraudsters. Steve mentioned about receipts and you know financial documents, bank statements which can be generated and deepfake to look totally genuine. So you know the opportunities for fraudsters out there are immense um in how they use AI. And you're right, it is increasing. It is developing all the time, the technology, the capability.
Speaker: So the message we give is that people have got to be aware of that and they've got to realize and double check. And, and you know, it is a system now where you've got to actually think any communication, anything you get, could it be fake? How can I confirm before I trust it?
Speaker: And that's really the world that we're we're going into. You mentioned there about trust. I think that kind of leads into the next kind of part of this conversation. I guess when, you know, incidents of fraud happen, it can really diminish that trust between an individual, you know, whether that be with an organisation, with a public sector or a private sector. How can organisations, you know, really build that trust when they are tackling fraud? And, you know, how transparent should they be when an incident does happen?
Speaker: Yeah, you know, we read all the time about particularly recently data breaches, data hacks, companies who've had a cyber attack, you know, and and there is an increasing number of attacks. Why? Well, because, you know, we may not believe it, but the yeah UK is is a wealthy country. you know comparatively across the world. So we are a target for the world's fraudsters. There's other reasons why you know the UK is such a target. There was a recent report that suggested that in the UK um people are online on their devices, their their mobile phones, their laptops and iPads more than other countries in the world. So the likelihood of a fraudulent message being received read, opened up by somebody in the UK is more. um you know The second language of a lot of countries where these frauds are developed is English. So you know it makes sense that therefore communicating with an English-speaking country because they all already have that language capability. So we are a target. So we're a target for fraud. We're a target for cyber attacks as well.
Speaker: An increasing number of companies. um you know Recently we've heard of the Co-op, Jaguar Land Rover, Marks & Spencer, all had a cyber breach. And of course, once that data is stolen from those companies, it's sold on the dark web, fraudsters can buy it and then they can communicate with those individuals, pretending to be the company from who it's been stolen from. And if the individuals aren't aware of the data breach, then they're far more vulnerable to believe in the message that they get in from a company they may well regularly communicate with, Marks & Spencer for example. um Now, on those occasions, we were aware of those data breaches because it impacted on their business so much, similar to Jaguar Land Rover, that it's there, it's out in the public arena. But lots of companies who have data breaches, we're not aware of.
Speaker: um And I think that when that happens and people become aware and they haven't been notified, that erodes that public trust with those companies. So personally, i think that it's it's um it's more beneficial where they accept what's happened. you know there's ah There's a requirement for them to report data breaches to the Information Commissioner's Office, but the individuals whose data hasn't been stolen don't generally get informed.
Speaker: So you know that's perhaps something that we need to consider in the future. Yeah, um I fully support Steve's view on that. um The public need to be aware of potential data breaches.
Speaker: We also, on NHS type cases, we encourage publicity at the appropriate time when the case is in the public domain. We actively seek media reports on the positive criminal outcomes with the impact hopefully of deterrent effect and prevention effect for every pharmacist or optician that we happen to prosecute and convict in the criminal courts.
Speaker: There's hopefully another handful who will then think twice about carrying on with the frauds. As I said, it's a small minority. but seeking that publicity via the BBC, ITV or the Western Mayor of the local press you use is a positive aspect of it, but it's at the appropriate time. We obviously cannot seek publicity at an early stage of the investigation. We could be sure of our facts.
Speaker: All our cases are prosecuted via the Crown Prosecution Service. They provide the independent, impartial scrutiny. The case is suitable for criminal prosecution. um But I fully endorse what Steve has just said there about sharing the information with the public at the appropriate time. i think the example that Steve mentioned there, the Marks and Spencer's one, ah literally was conveyed to everyone within a few days, wasn't it? So people would be aware of any dodgy emails or content that you received from Marks and Spencer's.
Speaker: Be suspicious, think twice about it, don't just click the link and respond to it. And that's really key, you know, we're in the business of preventing fraud. 41, 42 or 43% of crime now is ah is ah is a fraud. um You know, the figures are constantly changing. But, you know, it's it's not far off.
Speaker: Half of all recorded crime is a fraud or a scam. So, you know, trying to reduce people's vulnerability is absolutely key. So, you know, making people aware of a data breach that you did has been stolen. You need to be aware of any incoming messages from that company. um you know, for me is a way that we can prevent fraud, prevent people becoming a victim simply by raising awareness and and and informing people of what's happened.
Speaker: So we've talked, you know, a lot about, you know, technology, AI, emerging trends and things like that. I guess look into the future then, how can organisations kind of prepare themselves better for what's to come? Very difficult question. I know we can't look into the future, but I guess what what advice would you give organisations in terms of how they can be preparing themselves?
Speaker: ah I think fraud is evolving faster than ever, to be honest. I mean, it's if it was a business, it'd be one of the world's leading businesses, I think. um Fraudsters are innovative.
Speaker: with their technology, their AI, even their global ne networks. um So we must try as much as we can to match them.
Speaker: If you stand still, you'll get left behind. We need to be innovative, collaborative and anticipate what we perceive to be going ahead. And certainly within Welsh Government,
Speaker: We regularly, with all our departments and areas of business, provide risk assessments. And I ask the staff there, if you were going to commit fraud against the Welsh Government yourself, how would you do it?
Speaker: And then the risks will become apparent, um some more prevalent than others. Then you can put controls in place. to stop or mitigate that. and And then of course through you know the transparency of your investigations once they're out there and if you get a conviction, that that's a great deterrent.
Speaker: But it's learning from lesson lessons learnt if you like from that to also increase your controls. And within Welsh Government I can only speak for that. Those fraud risk assessments ah must come to me twice a year.
Speaker: So they're regularly reviewed, updated, because fraud is an evolving practice and those fraud risk assessments must be living documents. So I would say more proactivity and at the risk of getting shot, more resources into fraud because with the evolution of technology, we need more skills, not less, and that goes for Welsh Government, and NHS and, dare I say, the police having been there but previously.
Speaker: Yeah, I certainly advocate an innovative approach. The old style investigation and seeking publicity on the criminal sanctions is fine. However, i think we need a more risk-based approach which identifies the system weaknesses that enable the fraudsters to commit the frauds.
Speaker: And then we can deal with those system weaknesses when at a time, how many dozens of of cases gone on going. And also extrapolate the potential savings. If the fraud hadn't been identified, would it have carried on for another 12 months, another two years?
Speaker: And those savings, which are identified via the extrapolation process, can then be used to justify increased investment? Because everything that Steve has mentioned here today about the data analytics, they don't come cheap.
Speaker: You need to invest in proper resources, the auditors, the data analysts, the computer experts, they all require significant investment. I think that's the way forward really, as well as... verscans they They do, hopefully. And if you can demonstrate that by using the extrapolated savings,
Speaker: that would justify that. ah As I mentioned earlier in general conversation, I'm aware that my colleagues in NHS England have got funding from central government for something called Project Athena, which is guaranteeing a 5 to 1 return on the initial investment of £12 million pounds on data analytics, identifying the outliers, the investigations and the recoveries, the civil recoveries,
Speaker: And that has been a massive success in this first year. And then subsequently, they will take forward that investment in the following years. Thanks, Graeme. Really interesting to hear about Project Athena. Perhaps we can pop a link to that alongside the podcast for people to learn more about the project. Steve, it's been a fascinating conversation today. It feels like it's really flown by and but we are at our final question now. So I wanted to ask each of you, what would be the one key message you'd like those listening today to take away from our conversation?
Speaker: Okay, from a Welsh Government point of view, but it transcends boundaries as well. Stand still and you'll fall behind. be innovative, collaborative and anticipate.
Speaker: And I would just reinforce the message of the government strategy, stop think fraud. Any messaging that you deceive, be it a phone call, be it a text message, be it ah an email, just stop, look at it and think is that genuine? And always consider that it's somebody who's fraud lately trying to steal your money. And I always say that the frauds has only contact you in order for you to do something to help them steal your money because if they could steal your money without contacting you they would so they're reaching out to you because you've got to help them by clicking on a link by putting your bank details in by putting a password in by moving money from one account to another account by trusting a message that you've got saying that bank account details have changed and you now need to move it to a different bank account so all those are strategies that they employed to try and get you to move your money or provide personal data that will help them steal your money So stop think fraud and don't help them steal your money.
Speaker: think my main message is that if you suspect the fraud or any economic crime is ongoing in the NHS in Wales, then please report your suspicions. Don't be afraid to report your suspicions if they're genuine.
Speaker: And there may be a genuine explanation as to what why you think there's fraud ongoing. So, report it via the Fraud and Corruption Reporting Line, which is maintained by the and NHS, or the online reporting line, and we can then look into it, and we will do the investigation. Do not investigate it yourself.
Speaker: And if you've tried to report it via your line manager who hasn't taken any actions, then please report your concerns, and we will deal with it. Just a really quick point on that, Graham. Is there protection for people that report concerns? Is that might be something people are a bit concerned about?
Speaker: We encourage people to leave their details so we can follow up on things, but we also ah encourage people to leave information anonymously if they want to. So they don't have to identify themselves for obvious reasons. You wouldn't want your colleague to know that you've reported that.
Speaker: um But no, there's no whistleblower protection under PIDA. um as As Steve mentioned, report any fraud um to action fraud and we continue to investigate it. But um for us, a lot of it is around collaboration, partnership working. No single organisation tackle fraud alone. um and prevention as well. So as I said, we can investigate fraud um and we will, and we do, um but prevention I think is vital um and it'd probably be a ah lot more impactful than um investigation alone. As I've already said, I've thoroughly enjoyed today. It's been a really, really interesting conversation and I really appreciate the time of our panel today. So a big thank you to you all.
Speaker: Thank you to Rachel Kostic, to Steve Tooby, to Graham Dainty and Steve Benson-Davidson. Thank you for joining us today.
Speaker: Die Elchen Wau.
Speaker: Thanks for tuning into this episode of the Exchange Podcast. If you enjoyed it, then hit subscribe via your podcast provider to catch future episodes. A quick review and share with your friends or colleagues would mean a lot to us.
Speaker: For more information, check out the show notes. You'll find all the relevant links and contact details there. You can also visit our website at audit.wales. If you have any questions or thoughts, we'd love to hear from you.
Speaker: you

