Wednesday, December 15, 2010

Practical steps to protect your business against Bribery and Corruption

Policies

Develop policies to provide practical guidance for all employees on acceptable business practices covering:
• Business ethics – to create a culture of ‘doing the right thing’.
• Conduct and how to deal with conflicts of interest.
• Gifts and hospitality

Processes

Ensure that policies are embedded into normal business practices:
• Undertake independent due diligence of all third-party agents and others who are in a position to pay bribes business.
• Ensure that all third-party agents and intermediaries comply with your organisation’s business policies and procedures.
• Review the management of indirect sales channels (eg, agents, advisors, consultants and distributors).
• Include in your terms and conditions of trade the standards of ethical behaviour that you expect of joint venture and other business partners.
• Maintain accurate and timely records of all transactions related to third parties especially in the sales and procurement areas of the organisation.
• Establish mechanisms to enable significant issues to be escalated within the organisation.
• Undertake regular reviews and conduct appropriate audit of relevant business processes to ensure that they remain up to date and corruption risk is identified.


People

The commitment of staff is crucial to the success of your business policies and processes. To this end:
• Set the ‘tone from the top’ as one of zero tolerance towards bribery, corruption and other related crimes.
• Assign specific responsibilities to the board and senior management. Ensure appropriate oversight and adherence to policies and processes.
• Introduce and maintain a credible mechanism for employees to report concerns.


Communication

Ensure that staff and third parties (including customers and suppliers) are fully aware of company policy:
• Communicate clear simple messages across cultures and languages.
• Introduce full disclosure on policy, process and breaches in all reports.
• Ensure disciplinary policy on breaches is communicated and enforced.
• Implement appropriate and ongoing training and education programmes.



Sourced from Fraud Advisory Bureau

Wednesday, November 17, 2010

Identity Fraud

The term ‘identity fraud’ is commonly used to describe the impersonation of another person for
financial gain. Fraudsters steal your personal identity and/or financial information and use it to
purchase goods and services or to access facilities in your name.

What is identity fraud?

Fraud occurs ‘when a false identity or someone else’s identity details are used to support unlawful activity, or when someone avoids obligation/liability by falsely claiming that he/she was the victim of identity fraud’.

Common types of identity fraud

Application fraud/account takeover:

A fraudster applies for financial services (eg, a new credit card or opens a new bank account) in your name or changes your postal address.


Impersonation of the deceased:

A fraudster uses the identity of a deceased person to obtain goods and/or services.


Phishing:

A fraudster sends you an email claiming to be from your bank or other legitimate online business (eg, a shop or auction website) asking you to confirm or update your personal information such as passwords and account details via a link in the email.


Present (current) address fraud:

A fraudster living at your address (eg. the same block of flats) or nearby uses your name to purchase goods and/or services and intercepts the mail when it arrives.


How does the fraud work?

A fraudster steals or acquires information about you. This may include:
· Your name
· Your current or previous address
· Your date of birth
· Your bank account or credit/debit card details
· Any other personal or financial information about you
· This information is then used to:
· Acquire new debit, credit or store cards Open bank or mobile phone accounts Obtain new passports or driving licences
· Apply for benefits
· Take out loans
All in your name. You may not realise that you have been a victim of identity fraud for some time. This is because the fraudster may intercept deliveries or redirect your mail without your knowledge or consent.

The Identity Fraudster
1. Steals/acquires personal/financial information about you
2. Uses this information to obtain finance/goods/services in your name
3. Intercepts/redirects goods/services
4. You stop receiving mail or receive mail about goods/services you know nothing about


What happens if you become a victim?

Generally you will not be liable for all of the debt incurred by the fraudster in your name. However you will need to rectify the damage caused by the fraudster (particularly. to your credit rating) and this can take time. 5 steps that you should take:
1. Report the matter to the relevant organisation(s) immediately. Follow their advice.
2. Obtain a copy of your credit report (available from credit reference agencies).Check for discrepancies. Go back to step 1.
3. Keep a record of all correspondence you make or receive in respect of the identity fraud.
4. Consider ‘protective registration’. A small annual fee is charged for this service.
5. Reassess your personal security strategies in respect of your personal and financial information. (Ask yourself ‘how well do I protect it and can I do anything differently?’)

In most cases it will be at the discretion of the organisation which supplied the goods and services to the fraudster to decide whether or not to prosecute. This is because the organisation supplying the goods or services is considered the victim in law – not you.


How to protect yourself

Be aware of the risk from identity fraud and safeguard your personal and financial information.

DO:
· Securely destroy all documents containing personal information before disposing of them.
· Remove your name from unnecessary or unwanted mailing lists.
· Arrange for your mail to be redirected if you move house and notify relevant organisations.
· If you don’t receive any mail, check with Royal Mail that a redirection hasn’t been set up in your name without your knowledge.
· Monitor your bank accounts regularly for any unusual transactions and close any banks accounts you no longer need.
· Review your credit report on a regular basis.
· Report lost or stolen personal documents and/or credit/debit cards.
· Limit the number of personal documents you carry to those that you need – leave the rest at home in a secure place.
· Use secure passwords and PINs – a combination of numbers and letters is best. Shield the display when entering your PIN into a cash machine or mobile terminal.
· Install anti-virus software and firewalls on your computer and keep them up to date.
· Limit the amount of information stored on mobile devices such as phones, PDAs and hand-held computers.

DO NOT:
· Disclose personal information over the telephone (especially a mobile phone), on the internet, by mail or in person to people you don’t know.
· Respond to unsolicited emails.
· Disclose your passwords and PINs to other people, even to family members.
· Use obvious passwords or PINs or the same password for different accounts.
· Let your debit or credit card out of your sight in restaurants and shops.
· Disclose personal information on websites that are not secure.


Source: Fraud Advisory Panel

Wednesday, November 10, 2010

Fraud hotspots in smaller businesses

Small and medium-sized businesses (SMEs) are particularly vulnerable to fraud in times of economic downturn; many lack the controls found in larger organisations and do not necessarily have the resources to combat certain types of fraud. This factsheet highlights some of the key areas of fraud risk.

Areas of fraud risk

All types and sizes of businesses are vulnerable to fraud. Smaller businesses can be susceptible to a very broad range of fraud risks and a small workforce can mean that it is difficult to segregate duties. Fraud can be committed by employees (sometimes called ‘internal fraud’ or ‘employee fraud’), third parties (such as suppliers and customers) and even by business owners themselves. Some of the most common fraud ‘hotspots’ are summarised below.

Customers

Card fraud: A fraudster pretends to be a legitimate customer and purchases goods using a stolen credit or debit card.

Non-deliveries: Customers falsely claim that goods dispatched from an online retailer have not been received.

Refunds: Customers steal goods from a retail outlet and then return the goods for a cash refund.

Employees

False or inflated supplier invoices:
Employees authorise payments for overpriced and/or non-existent goods or services and receive a ‘kickback’ (such as a cash payment) in return from the supplier. This is particularly noticeable in the property management sector where service charges are calculated on a cost plus percentage mark-up basis.

Fictitious refunds or returns:
Employees generate false refunds and either steal the cash value from the till or arrange for the amounts to be refunded directly to their personal credit card or bank account. Retailers are particularly susceptible to this type of fraud.

Ghost employees or contractors:
Fictitious employees and/or contractors are added to the business’ payroll and are paid wages and/or expenses.

Misappropriation of assets:
Employees help themselves to cash, stock, IT equipment such as laptops, and stationery or submit false expense claims.

Theft or supply of confidential information:
Employees steal confidential customer and/or client information and use it for fraudulent purposes.

Suppliers

False or inflated invoices: Suppliers invoice for more goods or services than were delivered or supplied, or invoice at a higher price than originally quoted. This may involve collusion with an employee to ensure that payments are authorised.

Long firm fraud: A business is set up with the purpose to defraud other legitimate businesses.

Property management: Over-charging by management companies using fictitious time records.

Other third parties

Corporate identity fraud:

A fraudster sets up a false company to trade or steals an organisation’s identity and/or financial information and uses it to purchase goods and services, obtain information or to access facilities in that organisation’s name.

Online banking fraud:

A fraudster gains access to the business’ online bank account and manipulates funds such as setting up standing order payments to his/her own bank account. Businesses that do not have adequate firewall protection are particularly vulnerable to this type of fraud.

Fraud warning signs

There are a number of warning signs that can indicate that fraud may be occurring within your business. These include:
• Changes in employee behaviour
• Changes in cash flow
• Stock shrinkage
• Customer complaints
• High turnover of staff
• Computer and network problems

Managing the risk of fraud

Your business can take a number of steps to reduce the risk of becoming a victim of fraud. The key elements of fraud risk management are:

Prevention

• Establish an ethical business culture. Develop an anti-fraud policy that clearly sets out the minimum standards of
behaviour expected of employees (acceptance of gifts, use of assets, response to theft etc) and lead by example.
• Minimise the opportunities for fraud to occur within your business. Review your business activities; identify the areas most at risk to fraud and introduce controls to prevent it. These might include segregating finance duties, implementing authorisation thresholds, conducting reference checks on new employees and introducing IT systems access controls. Controls do not need to be complicated or expensive.

Detection

• Be aware of the indicators of fraud. Introduce procedures to detect the early warning signs that fraud is taking place. These might include educating staff to spot common frauds and scams, introducing a reporting hotline, conducting spot audits (of stock, sales and purchase ledgers etc) and reviewing profit and loss accounts on a regular basis.

Investigation

• Make sure you are prepared to respond to a fraud being discovered within your business. Smaller businesses should consider a policy that independent professional advice will be sought at the outset of any fraud investigation. Larger organisations should include fraud as part of their disaster recovery plan. This should cover the investigation process (who, when and how), legal or ethical duties to report (to your shareholders, customers, bank, insurance company and/or regulator(s)) and public relations.
• It is important to remember that there are different standards of proof that need to be met according to the type of action you wish to take against the fraudster – disciplinary, regulatory, civil or criminal.

Insurance

• Consider the need for fidelity or crime protection and/or directors’ and officers’ liability insurance.

Review

• Business practices and activities change over time. Regularly review the systems, processes and controls you have in place to manage the risk of fraud to ensure that they remain current, relevant and appropriate for your business’ needs.

Indicators of fraud checklist

There are a number of behavioural and financial warning signs that can indicate that there may be a problem within your business. These should not be taken as definitive proof that there is a fraud; some employees will display one or more of these characteristics and be completely honest and trustworthy; others may display none but may be dishonest.

Employee behaviour:

• Increased levels of stress without a high workload
• Lifestyle not commensurate with salary
• Reluctant to take annual holidays
• Personal financial problems
• Tends to bend/break the rules
• Tends to be subject to complaints
• Works late or unusual hours
• Is unwilling to delegate
• Refuses promotion
• Cosy relationship with contractors and/or suppliers
• New staff resign quickly

Financial:

• Cash only transactions
• Large variation in expenses between offices/outlets
• Poorly reconciled cash expenses
• Poorly reconciled customer accounts
• Customer complaints
• Rising costs with no explanation or that are not commensurate with an increase in revenue
• Large volume of refunds to customers
• Unusually large inventories

What to do if your business suffers a fraud

Three steps that you should take are:

1. Report the matter to the gardai and other relevant organisation immediately. Depending upon the type of fraud this could include your bank, insurance company, suppliers and/or customers.
2. Consider seeking specialist professional advice.
3. Reassess the way your organization conducts and manages its business to ensure it is adequately protected against this type of fraud occurring in future.

Tuesday, November 2, 2010

Fraud in a Recession

Economic recession


A downturn places people under pressure and leads some into dishonesty. Fraud losses make recession induced cashflow, liquidity and credit problems worse. Coping with the consequences of even a small fraud will consume energies when management time is already at a premium.

A recession increases fraud threats from inside the business, for example: Managers desperate to keep their heads above water may be tempted to falsify accounts and sales returns; Employees with large debts may inflate expense claims, ‘borrow’ from the till, steal stock and company assets and collude with customers, suppliers or Contractors: Staff may be more vulnerable to attempts to get them to sell confidential information; Organised criminals may infiltrate companies, placing individuals in positions where they have access to money, goods, or information that can be turned to financial gain.

Recession also brings to light existing frauds as credit lines run out and financial manipulation can no longer be concealed.

External attacks are equally serious. Companies providing customer credit are at risk from an increase in fraudulent applications. Suppliers and contractors will be under pressure and some will defraud business customers. As smaller firms find it harder to obtain credit from traditional sources they will be tempted to turn to new and untried sources of funding, some of which will be offered by fraudsters.


What to do if your business suffers a fraud

Three steps that you should take:

1. Report the matter to the police and other relevant organisations immediately. Depending upon the type of fraud this could include your bank, insurance company, suppliers and/or customers.

2. Consider seeking specialist professional advice.

3. Reassess the way your organization conducts and manages its business to ensure it is adequately protected
against fraud.



Remember that a recession is the time to take fraud seriously.

· Identify the areas of your business that might be most vulnerable to loss from theft or fraud, such as sales, stock, purchasing, expenses and record keeping.

· Strengthen any obvious weaknesses you have identified. This might include introducing additional checks for signing off payments or authorising purchases.

· Monitor your bank and credit card statements for unusual transactions.

· Designate a senior member of staff with responsibility for managing risk. He/she should identify areas of vulnerability and recommend changes to business processes where appropriate.

· Ensure that your business premises have adequate physical security protection including locks, keypads and alarms.

· Try to minimise cash transactions within your business.

· Conduct checks on your suppliers, contractors and biggest customers to make sure they are who they say they are and that you are getting value for money

· Check invoices against original purchase orders and the goods supplied.

· Make sure your staff are aware of the risks from theft and fraud and how to report it.

· Communicate staff expense policies/procedures and monitor compliance. Check references for all new staff; full-time, part-time, temporary, and casual. Further checks may be needed as employees are promoted or require access to more confidential information.

· Adequately protect your IT systems and business information from the cybercrime risks posed by phishing, viruses, hacking and scams.

· Consider how you would respond to a fraud if it was discovered in your organisation



What Do Not

· Forget that severe economic pressures can cause previously honest people to become dishonest.

· Assume all information provided by prospective employees, lenders or contractors is accurate.

· Economise on protecting your business against the risk of fraud.


Source; The Fraud Advisory Panel

Thursday, October 7, 2010

Wireless Safety

Wireless technology is now built into just about every gadget we’re likely to own – from mobile phones, PDA’s and laptops through to iPods, cameras and book readers. It is a functionality which is less a feature than a consumer requirement.
Always being connected especially when you’re on the move, can seem like a wonderful thing. You can surf the internet, write and pick up emails, download important files – everything you can do in the office or at home – wherever and whenever you wish. But all this comes at a price. The price is the security of your data.


Wireless communications offer a window of opportunity for the data thief

Mobile phones, PDA’s and laptops now come with two wireless technologies as standard: Wi-Fi and Bluetooth. Many people forget to turn this functionality off on their mobile and laptops when they are not in use. Mobile phones in particular are often switched on permanently because users don’t think to check. As a result their presence is advertised to other wireless users 300 feet away or more. Since the signals are always seeking connections they are easily discovered and unless properly secured, can be hacked in a matter of minutes.

Securing mobile Wi-Fi- computers

There is one very simple wireless security solution; turn if off if you are not using it. With most laptops, all it takes is a flick of a switch. Wi-Fi signals travel further then Bluetooth signals and this should be borne in mind especially in heavily populated areas.

One of the main risks with mobile Wi-Fi is that it can be configured to automatically connect to available networks. This puts your computer at risk as it may hop on to any free hotspot without notifying the user. All the potential hacker then needs is some free software, readily available on the internet, to steal passwords, contacts and other personal or confidential data.

Wi-Fi on the move- phones

The main security risk with mobile phones is Bluetooth.
Bluetooth transmissions work up to about 30 feet or more. Again in a public place this can advertise your presence and the fact that your device can be connected to and either hacked or hijacked.

Hijacking is a favourite ploy of many fraudsters. They can steal a mobile number silently and with great simplicity then use it to dial premium numbers for services which would be difficult to explain to a person’s spouse or partner. The resulting bill can be an equal embarrassment, with no way of proving to the service provider that it wasn’t the subscriber making the calls. The best way of staying secure is to switch Bluetooth off by going into the phone settings and disabling it.

Wi-Fi at home


Home wireless networks have a range of around 300ft indoors and 300ft or more outdoors, depending on a number of factors, including the strength of the transmitter and the number and type of obstructions in the way of the signal.
‘War driving’ is a common tactic used by fraudsters who drive around residential areas to identify and exploit weak home wireless networks for their own gain.
An easy way of making a wireless network more secure is to place the transmitter near the centre of the home, away from windows .Modern wireless networks come with certain security features built in eg. Firewall; The ability to encrypt traffic. These features should be enabled at set up.


How to protect yourself:


Always

  • Disable automatic connection on your computer to Wi-Fi networks.
  • Turn Wi-Fi off on your computer when it’s not in use
  • Turn the Bluetooth signal to ‘undiscoverable’ on your mobile phone when it is not in use.
  • Set a Bluetooth pass code on your mobile phone and change it frequently
  • Enable security features built into your wireless networks such as firewalls and encryption
  • Change the administrator name and password on your home wireless network
  • Change the default SSID (Secure Set Identifier) name at set up and disable broadcast.

    Never
  • Use the default settings on your wireless devices – the defaults are well known to hackers
  • Choose an obvious profile for your mobile phone
  • Pair your mobile phone with any Bluetooth enables devise that you do not recognise
  • Use default pass code settings, names or passwords on your mobile phone or wireless networks
  • Do not leave your home wireless networks turned on if you go away for any length of time.

Adapted from Fraud Facts, Wireless safety; Fraud Advisory Panel

Thursday, August 19, 2010

It's booker beware in the holiday lets market

This article was written by Sandra O'Connell and was published in The Irish Times Saturday 14th August 2010.

SANDRA O'CONNELL

Go Niche: THINK THERE’S nothing worse on holiday than bad weather? Try turning up and finding the villa you just forked out a fortune for doesn’t exist. Or exists but whose owners know nothing about your booking.

It’s a problem private investigator Annie Murphy of Bluemoon Investigations says is on the rise. She was recently engaged to unravel a particularly well-organised scam offering non-existent holiday lets in upmarket Puerto Banus (pictured).

“It was very professional. A number of properties were advertised through classified ads and on letting websites over a period of time. The guy on the end of the phone sounded very plausible. He said he was a quantity surveyor, and directed people to his own business website, which looked the part,” says Murphy.

It was only when people began arriving in Spain and found the properties didn’t exist that the scam became apparent.

By that stage the money had been transferred and the guy on the end of the phone line had stopped answering.

“Turns out his very professional website was made up of material lifted wholesale from two other quantity surveyor websites, including pictures of personnel,” says Murphy.

“The phone was an unregistered pay-as-you-go phone and the people behind the scam couldn’t be tracked down.”

Her advice is to be vigilant. “Avoid booking through classified adverts or from online adverts unless you already know someone who has booked that accommodation before with no problems and only ever make credit or debit card payments through secure websites,” says Murphy.

“If in doubt at all, do not make the booking or hand over any payment and, if a deal seems too good to be true, then it probably is.”

www.bluemooninvestigations.ie

Wednesday, August 4, 2010

I spy with my little watch

This article was published in the Independent Saturday July 31 2010

Be afraid. Be very afraid. They are watching you. Your phone could be bugged, your computer tracking your every key stroke and that harmless air freshener on the windowsill fitted with video recording equipment designed to catch you red-handed.
Forget international intrigue, James Bond, or the CIA. The new front line of hi-tech espionage is your office desk. And the spies are all around you.
So if you thought this summer's slippery and cerebral blockbuster, Inception, about the covert world of corporate espionage, was Hollywood fantasy, think again.
Just ask the Michigan couple who this week were accused of stealing more than $40m worth of trade secrets from their former employer, General Motors, and selling them to a Chinese car-maker.
Shashan Du (51) and her husband Yu Qin (49) were under covert investigation since 2006 and this week were charged with secretly downloading highly confidential insider information and selling it to the highest bidder. It is the latest in a growing number of high-profile cases of industrial espionage to hit the headlines.
"We are finding more businesses coming to us," says Annie Murphy of Bluemoon Investigations based in Dun Laoghaire. "Many suspect a particular individual is leaking information to a rival organisation or fear a competitor is trying to steal commercially sensitive information."
In fact, many managers have become so paranoid about the growing threat they do regular 'bug sweeps' of their premises. "Industrial espionage offers huge gains for the person carrying it out," says Murphy.
"We have found employees who want to steal information because they are about to start working for a competitor and others who simply want to try and sell the information. You would be surprised at how often this type of thing is happening."
This new army of mercenaries is equipped with hi-tech gadgets that would make even Mr Bond quiver with delight.
A quick visit to The Spy Shop (www.spyshop.ie) will reveal an Aladdin's Cave of sneaky snooping devices to help any wannabe spy or PI.
Technology, such as Spy Pen Cameras and Deleted Text Message Readers, has flooded onto the market to meet the growing demand.
"The equipment is just getting better and better," says Shane Doran of The Spy Shop. "And it's quite affordable now."
Some of the top sellers include the Covert Car Tracker, the Tissue Box Video Camera and Recorder and the Spy Watch with inbuilt video camera and recording equipment.
"The big change now is for recording systems," says Doran.
"In the past you would have had to have a camera, a power supply and then link it all up to a recorder. But now they all come in one and can be placed in most everyday devices and operated remotely."
One such device is the GSM Infinity Mains adaptor. It not only looks like a normal plug adaptor, but works like one. However, it secretly contains a hidden listening device that allows the owner to snoop from afar on conversations within a room by simply dialling the number of the SIM card located inside the device.
Bluemoon Investigations recently used similar hi-tech wizardry when contacted by a managing director concerned about the amount of fuel seemingly evaporating into thin air.
"It was a manufacturing company with a fairly large transport fleet where large volumes of diesel were unaccounted for," recalls Murphy. "However nothing was showing up on the closed-circuit cameras."
Bluemoon installed hi-tech recording devices around the premises and deployed undercover agents to infiltrate the very heart of the organisation.
"Following surveillance, our hidden cameras captured an employee selling the diesel to friends and local tradesman," reveals Murphy.
However, this didn't explain why there was no evidence on the company's own security cameras.
"One of our covert cameras recorded the company's security guard tampering with company's CCTV recording and removing the evidence. It also recorded him receiving his ill-gotten gains from the other employee for helping to cover up the theft."
Some companies have become so fearful of espionage they are turning the tables and giving employees they no longer trust phones with Bond-like capabilities.
The Spy Store (www.spystore.ie) sells the Nokia Spy Phone (€179.99), which, once switched to spy mode, becomes the ultimate snooping tool. You can leave the phone unattended and then dial into it to listen in on what is being said. The Nokia E51 Spy Phone (€549.99) is even sneakier. It not only allows you dial in and snoop, but to receive copies of every text message sent from the phone.
Although every self-respecting spy should be aware of Trojans bearing gifts, anyone looking to get their hands on such legally available products could find using them opens a dangerous legal minefield.
"You have to be careful you are not breaking any laws," says Murphy. "If an employee is using a computer to download sensitive information, there is software available that can detect and record their actions. Obviously if the company owns that equipment then they would be entitled to put software on the machine to see if any unauthorised activity is taking place. But you have to be careful you are not breaching anybody's human rights."
So if you are an employee with light fingers, a manager looking to sell company secrets or even a husband playing away from home, just be careful you don't get caught dangling in a web of technology.
Right now you're every move could be tracked and every word recorded. So wherever you find yourself just remember what the spider said to the fly -- "Will you walk into my parlour? 'Tis the prettiest little parlour that ever you did spy."
Irish Independent