Skip to content

Fraud in the workplace: prevention and detection

Common examples of fraud, typical contributing factors, best practices to avoid fraud, and how to detect and report fraud when necessary

Topics on this page:

What is fraud?

Fraud is any illegal act characterized by deceit, concealment, or violation of trust.

Common Examples

• embezzlement, misappropriation, or misapplication of University funds and/or property;

• forged signatures on cash-related forms;

• alteration or falsification of documents or computer files including time and attendance records, travel reimbursement requests, and reports to management or external agencies;

• diversion of drugs for personal use or resale;

• personal purchases charged to the University via PCard, Request for Payment, Travel Expense, or 312 Requisition, for example;

• conflict of interest: pursuit of personal benefit in violation of University Personnel Policy 113: Conflict of Interest;

• falsification of research data;

• breach of patient confidentiality;

• unauthorized disclosure of personal identifying information (PII);

• inappropriate billing practices

Contributing factors

Fraudulent activity can occur when an unethical person is working in an environment that lacks any of the following internal controls:

• management oversight

• segregation of duties (i.e. – authorization, custody, recording, and reconciliation)

• appropriate ledger review and reconciliation of accounts

• safeguarding of assets

• access control, both physical and systems

Most fraud is committed by trusted employees. As such, it can go undetected for extended periods of time. Verification is a necessary mitigating control when high trust is placed in an individual employee in a position of authority.

What you can do to help

Preventing fraud at the University is everyone’s responsibility. The use of proper internal controls can help prevent fraud from occurring or detect it sooner.

For example, you can:

• create or contribute to a culture that expects and models honesty;

• review work processes to identify opportunities to strengthen associated internal controls;

• implement or improve management oversight to offset known internal control weaknesses

 

It is the responsibility of each individual faculty or staff member acting on behalf of the University to comply with legal and regulatory requirements, policies, and procedures that apply to his or her position.

Policy 114: Compliance Education (excerpt)

Best practices to prevent or detect fraud

Trust is not an internal control. Rather, you should:

• review your ledger reports for unusual activity;

• safeguard cash (including checks), cash equivalents (PCards, gift cards), and other assets;

• assure adequate segregation of duties. When that is not possible, institute mitigating controls;

• provide management oversight when high trust is placed in an individual employee who holds a position of authority;

• revoke—immediately—physical and electronic access of terminated employees

What to do if you suspect fraud

If you have questions regarding the ethical propriety of any activity within your or another department, you should immediately report your concern regarding possible fraud to your supervisor or, if you prefer, feel free to contact any of the following offices to set up a confidential meeting to discuss your concerns. Every effort will be made to protect your confidentiality.

Members of the Department of Public Safety and the Office of University Audit staff have received specific training in conducting fraud investigations.

Due to the sensitive nature of a fraud investigation, and the need to preserve evidence, it is imperative that department management should neither attempt to conduct its own investigation, nor alert the suspected individual or others about a pending investigation.

Department of Public Safety
275-3333
www.security.rochester.edu

 

Office of University Audit (OUA)
275-2291
https://www.rochester.edu/adminfinance/audit/

If you prefer, you may instead call the Office of Human Resources, URMC Compliance Office, or the anonymous University Integrity Hotline to report your concern.

 

Office of Human Resources
275-2815

 

URMC Compliance Office
275-1609
www.urmc.rochester.edu/urmc/compliance

 

The University Integrity Helpline (anonymous)
756-8888

What a fraud investigation entails

The three main objectives of a fraud investigation are:

• verifying the facts;

• determining responsibility and accountability;

• recommending stronger internal controls to prevent similar acts from occurring—or to detect them on a more timely basis if they were to occur.

The University will share evidence gathered with the appropriate authorities to determine whether criminal action could be pursued.

How can University Audit help?

In addition to fraud awareness training and fraud investigation, the Office of University Audit provides a wide variety of audit and advisory services, including process and internal control reviews.

Related offices and departments

Other resources