Fraud and Corruption Control Plan 2026 to 2028
v1.0
Purpose. This plan sets out the fraud and corruption risks the department faces, the controls in place, the actions to strengthen them over the plan period and how performance will be monitored and reported to the audit and risk committee.
1.Context
The department pays about ninety million dollars in grants and a further sixty million under service agreements each year, regulates providers whose funding depends on its decisions and procures services from the market. These functions carry fraud and corruption risks from applicants, providers, suppliers and staff. The plan implements the fraud and corruption control policy and follows the Victorian Auditor-General's guidance on fraud control.
2.Key fraud and corruption risks
The fraud risk assessment completed in October 2025 rated the following risks as high or medium before controls. Each is recorded in the risk register with an owner and treatments. Risks must be reassessed every two years and after any substantiated fraud.
- False or inflated grant applications and acquittals
- Undeclared conflicts of interest in grant assessment and tender evaluation
- Collusion between staff and providers to overlook non-compliance
- Misuse of purchasing cards and false travel claims
- Manipulation of payment details to divert funds
- Unauthorised disclosure of confidential tender or compliance information
3.Prevention actions
Over the plan period the department will apply pre-award checks on every applicant and supplier, verify a sample of acquittals against source records, extend mandatory conflict of interest declarations to all inspection and audit work, and introduce data analytics on payment patterns. Segregation of duties between assessment, approval and payment will be reviewed in every branch by June 2027.
4.Detection actions
The department will run quarterly payment analytics for duplicate suppliers, changed bank details and split transactions, publish the reporting channels on the intranet and to providers, and review the allegation register monthly. Internal audit will test the grants and procurement controls in the 2026 to 2027 program.
5.Response actions
All allegations will be recorded within one business day and assessed within five. Investigations will follow the investigation procedure, be conducted by trained investigators and be reported to the audit and risk committee. Losses will be pursued for recovery and control failures will be fixed within the agreed date.
6.Awareness and training
Every employee will complete fraud and corruption awareness training on induction and every two years, and managers will complete the additional module on identifying red flags. Awareness sessions will be delivered to funded providers at the annual provider forum.
7.Monitoring and reporting
The fraud control officer will report progress against this plan, the allegation register and analytics results to the audit and risk committee each quarter and to the Deputy Secretary annually. The plan will be reviewed in November 2027.