Conduct a fraud risk assessment of the grants acquittal process
You are the Risk and Integrity Adviser in Corporate Services.
What has happened
Two events have unsettled the audit and risk committee: an acquittal irregularity at Wimmera Community Transport where supplier invoices appear duplicated across two grants, and an internal audit finding of undeclared conflicts among regional assessors. The committee has asked for a fresh fraud risk assessment of the grants acquittal process before its October meeting. The fraud and corruption control plan commits the department to verify a sample of acquittals and to introduce payment analytics, but the analytics tool is still in evaluation. Theo Lindqvist, the fraud control officer, wants the process mapped, the risks rated, treatments proposed and the risks entered in the register.
Deliverables
- Acquittal process map with control points
- Fraud risk assessment table with ratings before and after controls
- Treatment plan with owners, costs and dates
- Risk register entries
- Committee report
Documents to use
Systems to use
Risk, Incident and Security Register
Holds enterprise and program risks, fraud risks, security and privacy incidents and WHS incidents with ratings, treatments, owners and due dates.
Grants Register
Records every grant application from receipt through assessment, decision, funding agreement, payment and acquittal across the four programs.
Compliance and Investigations Register
Tracks inspections, complaints about providers, incident reports and investigations with risk rating, officer and compliance action.
Units of competency
Current on training.gov.au for the Public Sector Training Package as at 10 September 2026.
PSPFRU005Conduct fraud risk assessmentsPSPFRU007Implement fraud control activitiesPSPGEN134Coordinate risk managementPSPFRU013Anticipate and detect possible fraud activityPSPGEN143Prepare high-level written communicationQualifications
PSP50716Diploma of Fraud ControlPSP50122Diploma of GovernmentWhat to look for
Evidence guide
The process map should show real control points and gaps, and the risk ratings should be consistent with the matrix and explained. Treatments should be proportionate and specific, not generic, and should reference the analytics procurement and the declaration changes already under way. The committee report must be concise, lead with what is being asked, and be classified correctly. Look for evidence the student used the Wimmera case to test the controls.