Categories
Blog

The NBA Betting Scandal: Part 3 – A Compliance History of Basketball’s Betting Scandals

In 1951, the New York City College of New York (CCNY) basketball team stood at the pinnacle of collegiate glory. The Beavers had just achieved the impossible: winning both the NCAA Tournament and the National Invitation Tournament (NIT) in the same season —an accomplishment never repeated.

But within months, that glory turned to infamy. According to ESPN, what began as whispers of “odd plays” and “missed shots” would explode into one of the largest betting scandals in American sports history and would establish a pattern of ethical failure that has haunted basketball ever since.

From CCNY to Boston College, from Tim Donaghy to Terry Rozier, the story is not just one of athletes gone astray. It is a case study in compliance breakdown. Indeed, a lesson in what happens when integrity becomes a negotiable asset.

The CCNY Point-Shaving Scandal: The Original Sin (1951)

In the early 1950s, college basketball was America’s premier sport. Madison Square Garden was its temple. Gambling was its shadow congregation. The scandal began when New York prosecutors uncovered that players from CCNY, along with several other schools, including Kentucky, Long Island University, and Bradley, were “shaving points” in exchange for bribes from gamblers. They weren’t losing games intentionally; they were merely making sure the final score stayed within the betting spread.

It was a subtle corruption, and that is what made it so insidious. Seventeen players were arrested, including CCNY star Ed Warner and Kentucky’s All-American Bill Spivey. The fallout was immediate and devastating: CCNY dropped out of major college basketball, the NCAA banned Kentucky for the 1952 season, and the sport’s image was tarnished for a generation.

Compliance lesson: The CCNY scandal revealed that corruption does not always come from losing; it comes from compromise. The players rationalized their behavior as “not really cheating,” echoing the same rationalizations heard in every modern scandal:  “just a little inside tip,” “it doesn’t affect the outcome,” “everyone does it.”

Boston College and the Mob: Organized Corruption Returns (1978–79)

Nearly thirty years later, another college basketball powerhouse found itself in the crosshairs of organized crime. Once again, as reported by ESPN, the 1978–79 Boston College point-shaving scandal was orchestrated by notorious mob associates Henry Hill and Jimmy Burke, names later immortalized in Martin Scorsese’s Goodfellas. Hill recruited players to manipulate game outcomes for a New York-based betting syndicate. The scheme involved “shaving” small margins, losing by just enough to beat the spread, not enough to draw suspicion. Three players were implicated, including Rick Kuhn, who served four years in prison for his role.

What made the Boston College scandal different was its sophistication. The mob did not just bribe; it strategized, using statistical analysis and betting volume tracking—the early version of compliance risk modeling—but turned it inside out.

Compliance lesson: The Boston College scandal marked the point at which gambling corruption shifted from individual temptation to organized manipulation. The oversight mechanisms (if any) were reactive rather than preventive. The NCAA had no integrity infrastructure. Compliance, as a concept, did not yet exist in sports.

Arizona State and the Spread: The Modern Betting Market (1994)

By the 1990s, college basketball was big business, and so was gambling. The 1994 Arizona State point-shaving scandal reflected this evolution from local bookies to national betting markets. Two Arizona State players, Stevin “Hedake” Smith and Isaac Burton, were paid thousands of dollars to fix games for Las Vegas gamblers. Smith, the team’s leading scorer, was told to “miss a few shots” and “keep the score close.” Over several games, the betting lines swung wildly enough to draw the attention of sportsbooks, which reported the unusual activity.

The FBI stepped in. Smith eventually pleaded guilty to conspiracy to commit sports bribery and served time in federal prison. What made this scandal a watershed moment was not just the players’ involvement but also the detection and analytics of the data. Sportsbooks’ internal monitoring systems flagged the irregular betting volume. For the first time, technology, not whistleblowers, uncovered corruption.

Compliance lesson: Transparency through data can be a safeguard, if used properly. The Arizona State case demonstrated that integrity monitoring, akin to anti-money laundering analytics, could identify misconduct patterns before they metastasize. But it also showed that without ethical culture, monitoring is just a safety net under a collapsing bridge.

The Tim Donaghy Scandal: Corruption Inside the Whistle (2007)

The next great basketball scandal was not about players; it was about the referees. In 2007, NBA referee Tim Donaghy pleaded guilty to two federal charges: conspiracy to engage in wire fraud and transmitting betting information. Donaghy had bet on NBA games he officiated, and worse, according to ESPN, he provided insider information to gamblers about player injuries, officiating crews, and game dynamics.

The scandal rocked the NBA to its core. Commissioner David Stern called it “the most serious breach of integrity in the history of the game.” Donaghy served 15 months in prison, but the real damage was to public trust. The case exposed a blind spot: the NBA had no independent integrity oversight system. Donaghy’s access to inside information was unmonitored. His betting activity went undetected for years because there was no compliance-grade audit trail.

Compliance lesson: Even the enforcers need enforcement. When compliance is limited to the playing field, insiders with access to privileged information can exploit the system unchecked. It is the same lesson corporations learned from rogue traders and insider dealers: if your monitors are not monitored, integrity collapses from within.

The NBA’s Modern Reckoning: From Jontay Porter to Terry Rozier (2024–2025)

Fast-forward to today, and the NBA finds itself once again mired in scandal. The indictments of players like Terry Rozier and coaches like Chauncey Billups show that technology has advanced, but human rationalization has not. Players allegedly used non-public injury information to enable friends and associates to place lucrative “prop bets”; that is, wagers that, as Nate Silver notes, are “inherently more subject to manipulation”.

The irony is painful. The NBA helped legalize the very betting structures that now threaten its credibility. ESPN and FanDuel run ads during live games; team apps link directly to sportsbooks. A regulated industry has now replaced the oversight that once kept the mob out of basketball with conflicted incentives.

Compliance lesson: When your regulators are your business partners, independence becomes an illusion. This is the same governance flaw that led to Enron’s collapse, where auditors were paid by the companies they were supposed to oversee. In the NBA’s case, integrity enforcement depends on data and diligence from entities financially invested in the betting volume itself.

A Seventy-Year Pattern: From Street Corners to Algorithms

From the smoky backrooms of 1950s New York to the AI-driven betting apps of 2025, the story has not changed; only the tools have. Each generation of basketball betting scandals follows the same pattern:

  1. Information advantage exploited for profit.
  2. Ethical rationalization (“It’s not really cheating”).
  3. Compliance lag — oversight catching up after the fact.

The players, the technology, and the money evolve, but the root cause endures. When systems fail to align incentives, ethics, and oversight, integrity becomes a casualty of innovation.

Final Thought: Integrity Is the Ultimate Competitive Advantage

For compliance professionals, the through line from CCNY to the modern NBA is crystal clear. Every industry, sports included, faces a moment when it must choose between performance and principle. Basketball’s history teaches that when you gamble with integrity, you might win for a season, but you lose for a generation.

The compliance professional’s mission, whether in a Fortune 500 boardroom or a basketball arena, is the same: to make sure the game stays honest, the system remains fair, and the culture never forgets what’s at stake when ethics take a timeout.

Join us for our next blog post on Monday, November 3, as we consider the role of compliance in sports leagues.

Categories
Compliance Into the Weeds

Compliance into the Weeds: The NBA Betting Scandal – Lessons for the Compliance Professional

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the unfolding NBA betting scandal and explore what it all might mean for the compliance professional. 

Their discussion covers the allegations and implications involving high-profile NBA figures, including Terry Rozier, Damon Jones, and Chauncey Billups. They explore the role of material non-public information, the importance of risk assessment, the effectiveness of current compliance measures, and the crucial role of data analytics in detecting fraudulent activities. Insights into sports betting, preventive controls, and the ethical challenges faced by professional athletes are also discussed, drawing parallels for corporate compliance professionals.

 

 Key highlights:

  • NBA Betting Scandal Overview
  • Historical Context and Data Analytics
  • Conflict of Interest and Risk Assessment
  • Investigation and Compliance Strategies

 Resources:

Tom is writing a multipart series on the scandal on the ⁠FCPA Compliance and Ethics blog.⁠

Tom  

⁠Instagram⁠

⁠Facebook⁠

⁠YouTube⁠

⁠Twitter⁠

⁠LinkedIn⁠

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the ⁠Top 25 Regulatory Compliance Podcasts⁠ , a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has been conferred a Davey, a Communicator Award, and a W3 Award, all for podcast excellence. 

Categories
Compliance and AI

Compliance and AI: Inside AI Innovation: Jack Yu on Experian’s Cutting-Edge AI Solutions

What is the role of Artificial Intelligence in compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, Tom Fox interviews Jack Yu, Director of Product Management – Generative AI at Experian.

Jack shares his journey from exploring AI on his own to playing a pivotal role in Experian’s adoption of AI as an enterprise solution. The discussion delves into Experian’s strategic deployment of AI agents, their approach to responsible AI, and their efforts in fraud prevention using advanced AI technologies. Jack emphasizes the importance of transparency, collaboration, and continuous improvement in AI governance. The episode concludes with Jack’s enthusiasm for the future of AI and Experian’s commitment to combining innovation with responsibility.

Key highlights:

  • Jack Yu’s Professional Background
  • Journey into Generative AI
  • Experian’s Approach to AI Agents
  • Responsible AI and Governance
  • Fraud Prevention with AI
  • Future of AI at Experian

Resources:

Explore Experian

Experian on LinkedIn

Jack Yu on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
10 For 10

10 For 10: Top Compliance Stories For the Week Ending, October 11, 2025

Welcome to 10 For 10, the podcast that brings you the week’s Top 10 compliance stories in one podcast each week. Tom Fox, the Voice of Compliance, presents the compliance stories you need to know to end your busy week. Sit back, and in 10 minutes, hear about the stories every compliance professional should be aware of from the prior week. Every Saturday, 10 For 10 highlights the most important news, insights, and analysis for the compliance professional, all curated by the Voice of Compliance, Tom Fox. Get your weekly filling of compliance stories with 10 for 10, a podcast produced by the Compliance Podcast Network.

Top weekly stories include:

  • E-sports and the data privacy maze. (Bloomberg Law)
  • Does Homan have to return the $50K? (NYT)
  • Star witness in Menendez trial to be sentenced. (NYT)
  • Halkbank faces criminal charges. (FT)
  • Saudi mega-construction project under ABC investigation. (Semafor)
  • PE and the Ethics of Drug Research. (NYT)
  • $100MM wine fraud in NYC. (Bloomberg)
  • Crony capitalism and corruption. (NPR)
  • Johnson and Johnson ordered to pay $966MM in talc case. (NYT)
  • Trump is considering pardons for Maxwell and Diddy. (Reuters)

You can check out the Daily Compliance News for four curated compliance and ethics-related stories each day, here.

Connect with Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

You can purchase a copy of my new book, Upping Your Game, on Amazon.com.

Categories
Blog

Compliance Risk Assessment vs. Fraud Risk Assessment: Why the Distinction Matters

One of the most common points of confusion I see in the compliance space is the conflation of a compliance risk assessment and a fraud risk assessment. At first glance, they may look similar as both touch on governance, controls, and organizational exposure. Yet, as Jonathan Marks emphasized in a recent episode of the Data-Driven Compliance podcast, they are not the same. They serve different purposes, employ different methodologies, and generate different impacts. And if you blur the two, you may be leaving the corporate back door wide open.

In this post, I aim to explore the distinctions, explain why they matter, and demonstrate how both assessments complement one another in building a stronger, more resilient compliance program.

Compliance Risk Assessment: Coloring Inside the Lines

A compliance risk assessment is the backbone of the compliance function. It answers the question: Are we following the laws, regulations, and internal policies to which we are required to adhere?

The methodology is structured around:

  • Identifying obligations — What laws, regulations, and internal codes apply to our business?
  • Assessing exposure — Where are we most likely to be out of compliance?
  • Evaluating controls — What policies, procedures, and safeguards exist to manage those obligations?
  • Prioritizing remediation — Which gaps carry the greatest legal, financial, or reputational risk?

The Department of Justice (DOJ) has long framed this as a “three-question test”: Is your program well designed? Is it implemented in good faith? Does it work in practice? A compliance risk assessment is the diagnostic tool that helps answer these questions.

Consider this: a compliance risk assessment ensures that the organization operates within the bounds of the law. It helps the business avoid the unintentional missteps that could land it in hot water with regulators.

Fraud Risk Assessment: Thinking Like a Fraudster

By contrast, a fraud risk assessment is not about whether you are following the rules; it is about whether someone could deliberately break them, deceive the organization, and benefit at its expense. Marks put it succinctly: compliance without fraud detection is like locking the front door while leaving the back door wide open.

A fraud risk assessment is built around three key elements:

  1. The Act – The fraud scheme itself. Examples include false vendor setups, revenue inflation, insider collusion, or misuse of restricted funds.
  2. The Concealment – How the scheme is hidden. Fraud is rarely obvious. It may involve falsifying documents, manipulating data, overriding controls, or exploiting process weaknesses.
  3. The Conversion – How the perpetrator benefits. Whether through cash, bonuses, promotions, or reputational gain, there is always a payoff.

This approach is fundamentally about mindset. A compliance risk assessment looks at processes. A fraud risk assessment forces you to think like the fraudster, the “mind behind the crime.”

Methodological Differences

Marks emphasized that while compliance risk assessments and fraud risk assessments may overlap, their methodologies diverge in several important ways:

  • Focus on Intent vs. Process
    • Compliance asks: Are we following the rules?
    • Fraud asks: Could someone intentionally subvert the rules, and would we detect it in time?
  • Scope of Risk
    • Compliance focuses on legal and regulatory exposure.
    • Fraud encompasses a broader range of threats, including financial, operational, and reputational risks—whether driven by insiders or outsiders.
  • Tools and Techniques
    • Compliance assessments often rely on surveys, documentation review, and structured interviews.
    • Fraud assessments utilize forensic tools, including analytics, behavioral red flags, and targeted scenario testing, to identify potential risks.
  • Outcomes
    • Compliance assessments typically produce policies, certifications, and gap analyses.
    • Fraud assessments deliver actionable detection and deterrence strategies.

Red Flags: The Early Warning System

One of the most practical contributions of a fraud risk assessment is its focus on red flags, the early warning signs that something is not right. Marks categorized them into four groups:

  1. Data Red Flags – Unusual transaction timing, frequency, or amounts.
  2. Document Red Flags – Missing or altered records, incomplete approvals.
  3. Control Red Flags – Inadequate segregation of duties, override of established processes.
  4. Behavioral Red Flags – Employees living beyond their means or facing personal stressors.

The key is not simply to identify these red flags, but to connect them back to your control environment. Are your controls designed to catch intentional deception or only unintentional error? Too often, organizations rely on compliance-oriented controls that were never built to stop someone determined to cheat the system.

Skills and Experience Matter

Another critical difference lies in who conducts the assessment. Compliance risk assessments often require individuals with expertise in law or regulation. Fraud risk assessments, however, require a different skill set; professionals who understand fraud schemes, internal controls, and forensic techniques are needed.

As Marks bluntly put it: certifications are nice, but experience is essential. Those leading fraud risk assessments need to have “skinned their knees” in real-world situations to understand the difference between a red flag and a false signal. Without that expertise, organizations risk a paper exercise that fails to capture the real threats.

Complementary, Not Substitutes

It is tempting for organizations to assume that a compliance risk assessment also covers fraud risk. That is a dangerous misconception. While the two assessments intersect, they are not substitutes. A compliance risk assessment confirms the rules are being followed—a fraud risk assessment tests whether someone could and would intentionally break those rules for personal gain.

Together, they create a multidimensional view of risk:

  • Compliance risk assessments keep the organization lawful.
  • Fraud risk assessments keep the organization safe.

When aligned, they reinforce one another. For example, fraud red flags can be embedded into compliance training, transforming static learning into practical, scenario-based awareness. Compliance findings can inform fraud detection by highlighting areas where processes are weakest.

Beyond Reports: Building Organizational Resilience

The ultimate value of both types of assessments lies not in the reports they generate but in the resilience they build. Marks is right to stress that neither should be treated as a “set it and forget it” project. Both are living, breathing processes that evolve in tandem with your business model, regulatory landscape, and risk environment.

A well-executed fraud risk assessment provides a strategic roadmap for preventing, deterring, and detecting fraud early. A well-executed compliance risk assessment ensures that your program is not only designed and implemented but also functioning effectively in practice. Together, they enhance oversight, foster continuous improvement, and promote a culture of integrity.

Final Thoughts

The compliance community is rightly focused on regulatory risk, ensuring that policies, procedures, and obligations are met. But stopping there creates a blind spot. Fraud is intentional, adaptive, and motivated by gain. It exploits weaknesses not only in processes but in culture.

The lesson for compliance professionals is clear:

  • Do not assume that your compliance risk assessment covers fraud risk.
  • Invest in both assessments, recognizing their differences and complementary strengths.
  • Ensure the right people, with the right experience, are conducting each.
  • Embed fraud red flags into your training and compliance processes.

At the end of the day, compliance keeps you lawful. Fraud risk management keeps you safe. Organizations that appreciate the distinction and act accordingly will be better prepared to withstand the unexpected, protect their stakeholders, and build lasting trust.

Categories
10 For 10

10 For 10: Top Compliance Stories For the Week Ending September 27, 2025

Welcome to 10 For 10, the podcast that brings you the week’s Top 10 compliance stories in one podcast each week. Tom Fox, the Voice of Compliance, brings to you, the compliance professional, the compliance stories you need to be aware of to end your busy week. Sit back, and in 10 minutes, hear about the stories every compliance professional should be aware of from the prior week. Every Saturday, 10 For 10 highlights the most important news, insights, and analysis for the compliance professional, all curated by the Voice of Compliance, Tom Fox. Get your weekly filling of compliance stories with 10 for 10, a podcast produced by the Compliance Podcast Network.

  • A RadioShack Ponzi scheme. (Bloomberg)
  • Former French President Sarkozy received a 5-year sentence. (BBC)
  • Healthcare compliance, the FCA, and AKS. (Reuters)
  • Do you fantasize about leaving compliance?  (EFinancialCareers25)
  • Amber Energy wins CITGO auction. (Reuters)
  • DOJ shuts down bribery investigation of Homan. (HuffPost)
  • Two former Haitian officials were designated for bribery. (DOJ Press Release)
  • Singapore execs found guilty in Wirecard fraud. (FT)
  • Air India crash victims sue Boeing, Honeywell. (BBC)
  • Vietnam jailed a Parliamentary official for corruption. (Bloomberg)

You can check out the Daily Compliance News for four curated compliance and ethics-related stories each day, here.

Connect with Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

You can purchase a copy of my new book, Upping Your Game, on Amazon.com

Categories
10 For 10

10 For 10: Top Compliance Stories For the Week Ending September 13, 2025

Welcome to 10 For 10, the podcast that brings you the week’s Top 10 compliance stories in one podcast each week. Tom Fox, the Voice of Compliance, brings to you, the compliance professional, the compliance stories you need to be aware of to end your busy week. Sit back, and in 10 minutes, hear about the stories every compliance professional should be aware of from the prior week. Every Saturday, 10 For 10 highlights the most important news, insights, and analysis for the compliance professional, all curated by the Voice of Compliance, Tom Fox. Get your weekly filling of compliance stories with 10 for 10, a podcast produced by the Compliance Podcast Network.

Stories include:

  • NYT Magazine on Epstein and JP Morgan. (NYT)
  • Was it fraud or something else? (FT)
  • Citi and UBS settle with the CFTC over commodity trading compliance violations. (Bloomberg)
  • Goldman Sachs GC was once Epstein’s administrator. (WSJ)
  • The son of a Chinese regulator under investigation is detained. (FT)
  • Gen Z protestors force recognition of Nepali PM. (Reuters)
  • Using AI to detect AI-generated fake receipts. (NYT)
  • The challenges of responsible AI development. (Forbes)
  • Former Head of Security for WhatsApp Sues Meta. (NYT)
  • CFTC ends Enforcement Sprint. (ComplianceWeek)

You can check out the Daily Compliance News for four curated compliance and ethics-related stories each day, here.

Connect with Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

You can purchase a copy of my new book, Upping Your Game, on Amazon.com.

Categories
Daily Compliance News

Daily Compliance News: September 12, 2025, The Epstein and JPMorgan Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top stories include:

  • British Ambassador sacked over Epstein relationship. (WSJ)
  • NYT Magazine on Epstein and JP Morgan. (NYT)
  • Was it fraud or something else? (FT)
  • AfD offices raided for Chinese payments. (FT)
Categories
Blog

Fighting Fraud, Waste, and Abuse: Ten Lessons for the Compliance Professional

Fraud, waste, and abuse are often bundled together in compliance conversations, but they are not interchangeable. Fraud is intentional deception, waste is the careless misuse of resources, and abuse is the opportunistic exploitation of gray areas. Each carries unique risks. Each erodes value. And each, if left unchecked, creates fertile ground for corruption and regulatory exposure.

Throughout this series, we have examined each element in depth. Fraud remains the most familiar, often linked directly to corruption. Waste, though usually unintentional, drains millions from corporate coffers each year. Abuse occupies the murky middle ground where rationalizations and loopholes open the door to larger misconduct. Finally, we examined how an integrated framework, spanning from controls to culture, can help compliance professionals address fraud, waste, and abuse in a holistic manner.

What emerges is clear: fighting fraud, waste, and abuse is not an optional add-on to anti-corruption programs. It is central to them. Fraud cannot thrive without weak controls. Waste creates the conditions that foster corruption. Abuse normalizes rule-bending until bribery becomes a natural extension of it.

For compliance professionals, the question is not whether to address fraud, waste, and abuse but how. Here are ten key lessons that stand out.

1. Know the Difference

The first lesson is definitional clarity. Fraud, waste, and abuse often overlap, but they are distinct categories of risk. Fraud is intentional and prosecutable. Waste is careless and costly. Abuse is opportunistic and corrosive. Treating them as one dulls your controls. Compliance programs must tailor messaging, policies, and monitoring to each risk. For example, fraud requires forensic controls, waste requires efficiency metrics, and abuse demands cultural reinforcement. Clarity sharpens strategy and ensures that prevention is precise, not blunt.

2. Fraud Prevention Requires Strong Controls

Fraud rarely occurs in isolation. Bribery schemes rely on falsified invoices, manipulated expenses, or deceptive contracts. Preventing fraud means embedding strong controls: segregation of duties, third-party due diligence, mandatory job rotations, and robust hotlines. Data analytics adds another critical layer, identifying anomalies in billing, procurement, or expenses before they metastasize. Fraud prevention is not just about legal risk; it is about stopping corruption before it takes root.

3. Waste Is More Than Inefficiency

Waste may lack intent, but its impact is devastating. It drains profits, frustrates shareholders, and weakens culture. Waste in corporate travel, maintenance, or software licenses often reflects poor oversight and sends the wrong cultural message: accountability is optional. Compliance cannot dismiss waste as “just operations.” Regulators and boards increasingly demand stewardship. Waste that goes unchecked creates cover for fraud and abuse, turning inefficiency into risk. Compliance leaders must treat waste as a core governance issue, not an afterthought.

4. Predictive Analytics Is a Compliance Tool

Our review of Shell’s predictive maintenance program offers a powerful analogy for compliance. By embedding sensors and utilizing predictive analytics, Shell reduced waste, minimized downtime, and enhanced safety. Compliance can achieve the same results. Predictive analytics enables compliance officers to move from reactive investigations to proactive risk detection. Expense anomalies, hotline spikes, or vendor irregularities can be flagged in real time, preventing issues before they escalate. Predictive analytics is no longer a “nice to have.” It is the future of compliance risk management.

5. Abuse Is the Gateway to Fraud

Abuse thrives in gray areas, exploiting loopholes, stretching policies, or rationalizing questionable conduct. It often starts small, such as recreating a lost taxi receipt, but escalates when unchecked. AI-generated fake receipts illustrate how easily abuse morphs into fraud. Abuse corrodes culture by teaching employees that rules can be bent without consequence. Compliance must treat abuse as seriously as fraud, because, in practice, abuse is often a precursor to fraud. Ignoring it is an invitation to systemic misconduct.

6. Technology Must Match the Threat

Employees are already using AI to generate fake receipts. Compliance must use AI to detect them. Modern expense-auditing platforms now flag anomalies in fonts, metadata, or behavior patterns. Similar tools analyze procurement, payroll, and travel data for red flags. The lesson is clear: compliance cannot fight tomorrow’s threats with yesterday’s tools. Technology must evolve as quickly as the risks do. Matching technology to the danger is no longer optional; it is essential for credibility and effectiveness.

7. Culture Is the Ultimate Control

Policies and tools matter, but culture determines outcomes. Fraud, waste, and abuse thrive where accountability is negotiable, where entitlement is tolerated, and where corner-cutting is excused. Conversely, a culture of transparency and stewardship closes the space in which misconduct thrives. Compliance officers must partner with leadership to model integrity, reinforce accountability, and celebrate stewardship. Culture sends the clearest message: fraud, waste, and abuse are not tolerated here. Without cultural reinforcement, even the strongest controls will eventually fail.

8. Empower Whistleblowers as Early Warning Systems

Whistleblowers are often the first to spot fraud, waste, or abuse. Yet too many organizations undercut their own defenses by failing to protect or empower employees who speak up. Robust reporting channels, anti-retaliation policies, and timely follow-up are essential. In the fight against fraud, waste, and abuse, whistleblowers are not just informants; they are strategic allies. Empowering them demonstrates that the company values integrity, deters misconduct, and surfaces risks before regulators do.

9. Build Cross-Functional Coalitions

Fraud, waste, and abuse cut across silos. Fraud may surface in finance, waste may occur in operations, and abuse may be present in HR. Compliance cannot fight these battles alone. Cross-functional coalitions with audit, procurement, IT, and HR ensure risks do not slip through the cracks. Coalitions also strengthen messaging: stewardship is everyone’s responsibility. When functions share data, align incentives, and coordinate responses, blind spots shrink and resilience grows. Compliance professionals must position themselves as connectors across the enterprise.

10. Continuous Improvement Is Non-Negotiable

Fraud, waste, and abuse risks are not static; they are dynamic. Predictive models require recalibration. Fraud schemes evolve. Waste emerges in new technologies and processes. Abuse shifts as policies and cultures change. Compliance programs must continually improve by reviewing data, updating controls, and reassessing cultural vulnerabilities to ensure ongoing effectiveness. Static programs become obsolete, leaving gaps for misconduct to exploit. Dynamic, evolving compliance programs, by contrast, remain credible, resilient, and aligned with regulatory expectations.

Conclusion

Fraud, waste, and abuse represent a continuum of risks that, if left unchecked, will erode profitability, corrode culture, and undermine trust. Fraud is the most visible, but waste and abuse are equally insidious. Together, they form the ecosystem in which corruption thrives.

For compliance professionals, the fight against fraud, waste, and abuse is both a mandate and an opportunity for growth. By understanding the differences, strengthening controls, leveraging predictive analytics, addressing abuse early, deploying technology, fostering a culture of compliance, empowering whistleblowers, forming coalitions, and committing to continuous improvement, compliance can lead the fight.

The message is simple: fraud, waste, and abuse are not just a financial issue; it is also a compliance issue. When compliance professionals treat it as such, they not only protect their organizations from regulatory exposure but also create cultures of stewardship, accountability, and integrity. That is the true mandate of modern compliance to ensure that fraud, waste, and abuse cannot take root and that corporate integrity remains strong.

Resources:

Untangling Fraud, Waste, and Abuse: A Primer for the Compliance Professional

From Controls to Culture: Building Anti-Corruption Programs that Address Fraud, Waste, and Abuse

Culture, Costs, and Compliance: Tackling Corporate Waste with Data-Driven Solutions

Culture, Controls, and Consequences: Why Compliance Should Address Abuse Before It Escalates

Categories
Blog

From Controls to Culture: Building Anti-Corruption Programs that Address Fraud, Waste, and Abuse

Fraud, waste, and abuse are not just buzzwords in the government sector. They represent a real continuum of risk that every private sector company must confront. In fact, when designing or refreshing an anti-corruption compliance program, these three categories should not be seen as separate from bribery and corruption risks; they are integral to them. Bribery schemes thrive in environments where fraud is unchecked, where waste is tolerated, and where abuse of authority is normalized.

A truly effective anti-corruption compliance program, therefore, must address fraud, waste, and abuse head-on. Each requires different tools, but all rest on the same foundation: clear expectations, adequate controls, data-driven monitoring, and a culture of accountability. Yesterday, we took a deep dive into the three concepts behind fraud, waste, and abuse. Today, we continue our primer on fraud, waste, and abuse for the compliance professional by exploring how compliance professionals can operationalize their ABC framework to help fight these corporate scourges.

1. Fraud Prevention: Strengthening the Control Environment

Fraud sits at the heart of most corruption schemes. Bribery rarely occurs without the use of falsified invoices, fraudulent expense reports, or deceptive third-party contracts. That’s why fraud prevention measures must be embedded directly into your anti-corruption compliance program.

Practical steps include:

  • Segregation of duties. No single employee should have the authority to control both vendor approval and invoice payment. Splitting responsibilities closes off avenues for concealment.
  • Mandatory rotations or vacations. Employees in high-risk positions, such as procurement or finance, should be required to take periodic breaks. This not only reduces burnout but also increases the chance of uncovering irregularities.
  • Third-party due diligence. Vendors, distributors, and consultants are often used as conduits for corrupt payments. Screening them for red flags of fraud and corruption is essential.
  • Hotlines and reporting mechanisms. Anonymous channels encourage employees to report fraudulent or corrupt activity before it escalates.

Finally, modern fraud prevention is inseparable from data analytics. Reviewing transactions for anomalies in billing, procurement, or travel can help compliance officers identify both fraudulent activity and corruption red flags early.

2. Waste Reduction: Linking Efficiency to Integrity

Waste may not sound like a corruption risk at first, but it often creates the environment in which corrupt practices thrive. When organizations tolerate careless spending or redundant processes, they signal that accountability is optional. Waste becomes the fertile soil in which corruption can take root.

Practical steps include:

  • Cross-functional accountability. Compliance should collaborate with finance, procurement, and operations to ensure efficient allocation of resources.
  • Tracking key waste indicators. Duplicate software licenses, unnecessary travel expenses, or high energy consumption may not be fraudulent, but they represent vulnerabilities that can be exploited. Left unchecked, they normalize sloppy practices that corrupt employees can exploit.
  • Integrating waste metrics into compliance dashboards. If a business unit consistently demonstrates waste, it may also be vulnerable to bribery risks, particularly in operations that are heavily reliant on procurement.

By spotlighting waste, compliance leaders not only save the company money but also reinforce a culture of stewardship and integrity, two qualities that reduce the likelihood of corruption.

3. Abuse Control: Guarding Against the Gray Areas

Abuse often serves as the gateway to corruption. It thrives in gray zones, where managers stretch policies, exploit loopholes, or turn a blind eye to questionable behavior. Abuse may not always cross a legal line, but it corrodes culture and opens the door to bribery and unethical decision-making.

Practical steps include:

  • Tone from the top and middle. Executives and line managers alike must model integrity. If leaders exploit perks or bend rules, employees will assume similar behavior is acceptable in dealing with third parties.
  • Policy clarity. Abusive practices often hide in vague policies. For example, a travel policy that allows “reasonable upgrades” without definition invites abuse. Aligning policies with anti-corruption standards closes these loopholes.
  • Incentive structures. Embedding transparency and fairness into performance reviews and rewards ensures managers do not cut ethical corners to hit financial targets.

By shrinking the space in which abuse can thrive, companies make it more difficult for corrupt practices to become normalized.

4. Leverage Data Analytics: Uncovering Patterns Across Risk Categories

Corruption schemes are rarely isolated. They often weave together fraud, waste, and abuse. That’s why analytics should not be siloed. A robust anti-corruption program integrates monitoring across multiple risk vectors.

Practical applications include:

  • Travel and entertainment analytics. Reviewing expense reports can uncover fraudulent receipts, wasteful spending, or abusive upgrades. These same reports may also reveal bribery risks if entertainment involves government officials or high-risk clients.
  • Procurement analytics. Comparing vendor pricing across regions may reveal fraudulent invoicing, excessive costs (resulting in wasteful spending), or favoritism (abuse of power). It can also reveal third parties that may be used as conduits for corruption.
  • Cross-data integration. Linking procurement, HR, and finance data highlights unusual patterns. For example, a sudden spike in overtime in a high-risk market may flag both payroll abuse and potential red flags for corruption.

Data analytics transforms compliance from a reactive to a proactive discipline, catching issues before they metastasize into a full-blown corruption scandal.

5. Whistleblower Empowerment: The Human Early Warning System

Even the most advanced controls and analytics cannot replace human intelligence. Employees are the first to notice when fraud, waste, or abuse is occurring. But unless they feel safe speaking up, those observations remain hidden.

Practical steps include:

  • Robust reporting channels. Multiple options, including hotlines, digital portals, or direct reporting to compliance, all make it easier for employees to raise concerns.
  • Protection against retaliation. Employees must trust that speaking up won’t cost them their careers. Policies must be clear, and enforcement consistent.
  • Timely follow-up. When employees report fraud, waste, or abuse, prompt investigation and feedback demonstrate that the company takes reports seriously.

In the context of anti-corruption compliance, whistleblowers are invaluable. They can flag bribery schemes before external regulators or auditors uncover them.

Building Resilience by Tackling All Three

An anti-corruption compliance program that focuses only on bribery risks but ignores fraud, waste, and abuse is incomplete. Fraud fuels corruption, waste fosters the conditions where it flourishes, and abuse normalizes the behavior that enables it.

By embedding fraud prevention, waste reduction, abuse control, data analytics, and whistleblower empowerment into your anti-corruption framework, you create a resilient program that goes beyond compliance checklists. You demonstrate stewardship to shareholders, accountability to employees, and integrity to regulators.

The fight against corruption is not won by policing bribery alone. It is won by creating a culture where fraud, waste, and abuse cannot survive and where transparency, efficiency, and fairness are the norm. That is the true mandate for today’s compliance professional.