Skip to main content
Visit Scotland | Alba

Looking for advice and support to start, improve, grow, or promote your business? View our Business Support Hub.

1. Why have a policy?

Guidance issued by the Scottish Ministers to public bodies like VisitScotland on the proper handling and reporting of public funds includes a requirement to have a policy statement and response plan to address the likelihood of fraud.

In addition to this guidance, The Economic Crime and Corporate Transparency Act 2023 (ECCTA) came into effect on 1st September 2025 and created a new corporate offence of “failure to prevent fraud”. Legislative guidance on this is contained within the anti-criminal finance policy.

Read our anti-criminal finance policy.

2. Introduction

This policy gives guidance on VisitScotland’s commitment to the prevention, detection, reporting and handling of fraud within VisitScotland. Furthermore, it also considers VisitScotland’s risk assessment in relation to fraud and provides guidance on proportionate prevention procedures.

VisitScotland is committed to ensuring that opportunities for fraud, both internal and external, are reduced to the lowest possible level of risk.

Employees are required at all times to act honestly and with integrity and to safeguard the public resources for which they are responsible. VisitScotland will not accept any level of fraud, and any case will be thoroughly investigated and dealt with appropriately.

3. Definition of fraud

The term "fraud" is used to describe such acts as deception, bribery, forgery, extortion, theft, conspiracy, embezzlement, misappropriation, false representation, concealment of material facts, financial or professional malpractice and collusion.

Fraud is usually used to describe depriving someone of something by deceit, which might either be straightforward theft, misuse of funds or other resources, or more complicated crimes like false accounting and the supply of false information.

This also extends to the use of VisitScotland’s name or other details, whereby another person or body attempts to pass themselves off as VisitScotland.

It also applies when an individual or body attempts to present themselves as someone they are not, for example, falsely represents themselves as a legitimate supplier.

Computer fraud is where IT equipment (including the use of AI) has been used to manipulate programs or data dishonestly (for example, by altering, substituting or destroying records, or creating spurious records), or where the use of an IT system (including the use of AI) was a material factor in the perpetration of fraud.

Theft of data or fraudulent use of computer time and resources is included in this definition.

Employees are directed to the Data Protection Policy, and the IT Acceptable Use Policy, which prohibit the use of USB “flash drives” for any extraction of personal or business sensitive data and the Generative AI (Artificial Intelligence) Policy.

Historically, most internal fraud in organisations such as VisitScotland has been linked to claims for travel and subsistence and overtime, recording of cash receipts, irregularities in procurement procedures and the abuse of flexible working hours.

Examples of external fraud include providing false information in applications for grants or other forms of assistance, suppliers offering bribes or inducements and submitting bogus invoices.

VisitScotland has experienced attempts in the past of external fraud whereby individuals have presented themselves as legitimate suppliers to secure payment from VisitScotland or where individuals have presented themselves to a third party as “VisitScotland”.

In all cases VisitScotland will investigate and take relevant action to avoid the loss of VisitScotland monies and also protect the reputation of VisitScotland.

The Bribery Act 2010 requires organisations to demonstrate that they have “adequate procedures” in place to prevent bribery.

This topic is addressed in VisitScotland’s separate over-arching Anti-Bribery and Corruption Policy, which embraces a number of other more detailed policies.

VisitScotland have identified the following business-as-usual activities as particular risks for our organisation in respect of fraud:

  • Making payment to suppliers.
  • Making payment to contractors.
  • Making payment to employees.
  • Making payments in cash on familiarisation (“Fam”) trips or other similar activities.

4. Prevention

Managers and employees must always be alert to the risk of fraud, and other forms of theft.

Danger signs of internal fraud include evidence of excessive spending by employees engaged in cash or contract work, inappropriate relationships with suppliers, reluctance of employees to take leave, requests for unusual patterns of overtime and where there seems undue possessiveness of records.

Junior employees should resist any pressure from line managers to circumvent internal controls or to over-ride control mechanisms. Such action could be indicative of fraudulent activity and should be reported.

A key preventative measure in the fight against fraud is to take effective steps at the recruitment stage. Written references will always be taken up and independent confirmation of any professional qualifications will be obtained before offers of employment are made.

Candidates are asked to highlight any known or perceived conflicts of interests at recruitment stage.

Another preventative measure is the requirement for all employees and Board members to disclose any personal engagement with other organisations and bodies through the Register of Interests process. This is reviewed a minimum of annually.

It is also utilised during the recruitment and procurement processes to ensure conflicts of interest are identified and flagged, to minimise the likelihood of fraud occurring.

VisitScotland is committed to ensuring that it takes effective measures for implementing and maintaining effective and efficient internal controls in computer systems.

There is a need to ensure that the risks associated with new technology such as hacking, virus infections and fraud arising from the use of networks (whether local, national or international) are addressed.

Further information can be found within the Information Security Policy and IT Acceptable Use Policy.

Other measures designed to prevent and detect fraud include clear financial procedures, control systems, reconciliations, segregation of duties, supervisory checks and authorisations and an internal audit programme.

VisitScotland participates in the National Fraud Initiative (normally bi-annually) with data of our suppliers and employees uploaded to the NFI database where it is cross checked against records held by other public sector bodies, including local authorities.

Any matches flagged on VisitScotland data are investigated by the Finance team with appropriate steps taken depending on the outcome of these investigations.

If further action is required by VisitScotland in relation to potential frauds these are processed through the Fraud Response Plan. VisitScotland’s participation in the NFI exercises supports our counter-fraud approach.

5. Avenues for reporting fraud

VisitScotland has clear avenues for reporting suspicions of fraud. Employees should report such suspicions to the Fraud Response co-ordinator and should refer to the VisitScotland Fraud Response Plan (which is held in a different document and available on the intranet).

All matters will be dealt with in confidence and in strict accordance with the terms of the Public Interest Disclosure Act 1998. This statute protects the legitimate personal interests of employees.

VisitScotland also has a Whistleblowing Policy which encourages employees to raise concerns about issues such as malpractice, unlawful activities or dangers to colleagues and the public.

6. Responsibilities

Scottish Ministers

Responsible for issuing relevant guidance in the Scottish Public Finance Manual (SPFM) on the prevention, detection, reporting and handling of fraud. As a public body VisitScotland must implement this guidance and put appropriate procedures in place to prevent and detect fraud.

Board

The Board has corporate responsibility for ensuring that VisitScotland follows guidance issued by Scottish Ministers. It addresses key financial and other risks such as fraud through the Audit and Risk Committee.

Audit and Risk Committee

Oversees the risk management framework and governance arrangements on behalf of the Board. Therefore, the Audit and Risk Committee has a general responsibility for monitoring the operation and effectiveness of anti-fraud arrangements and requires regular reports on fraud activity.

Chief Executive

The Chief Executive is responsible for establishing and maintaining sound systems of internal control to support our policies, aims and objectives. The systems of internal control are designed to respond to and manage the whole range of risks that VisitScotland faces. Managing fraud risk will be seen in the context of the management of this wider range of risks.

The Executive Leadership Group

Support the Chief Executive by identifying those operational areas where the risk of fraud or other loss is greatest. This will help inform internal audit activities and should also provide pointers to where line managers should target their counter fraud measures.

The Fraud Response Co-ordinator

Is a nominated member of the Legal department and is the first point of contact for any suspected fraud within VisitScotland. This individual leads on all fraud investigations ensuring that the investigation is prompt and thorough.

The Head of Financial Services

Has been delegated overall responsibility for ensuring that necessary controls are in place for managing the risk of fraud in VisitScotland. Responsibilities include:

  • preparing relevant guidance on the prevention, detection, reporting and handling of fraud for issue to employees
  • establishing and reviewing an effective fraud policy and fraud response plan
  • ensuring that core financial systems are designed and operated so as to minimise the risk of fraud
  • coordinating assurances about the effectiveness of anti-fraud policies to support the Statement on Internal Control
  • ensuring that appropriate counter fraud training and development opportunities are available to appropriate employees
  • ensuring that appropriate action is taken to minimise the risk of similar frauds occurring in future
  • ensuring with the Head of Procurement that adequate supplier take-on and monitoring controls are in operation with appropriate internal segregation of duties

Internal Audit contractor

Is responsible for:  

  • delivering an opinion to the Board through the Audit and Risk Committee on the adequacy of arrangements for risk, control and governance (including those for managing the risk of fraud)
  • Promoting anti-fraud and anti-bribery best practice within VisitScotland and facilitating corporate learning
  • Considering fraud and corruption risks within their audit work, reviewing fraud prevention controls and detection processes put in place by management and making recommendations to improve those processes
  • ensuring that management has reviewed its risk exposures and identified the possibility of fraud as a business risk
  • assisting management in conducting fraud investigations

Managers

Across the organisation managers are responsible for:

  • ensuring that controls operate effectively and as intended, within their areas of responsibility
  • assessing the types of risk involved in the operations for which they are responsible
  • regularly reviewing and testing the control systems for which they are responsible
  • ensuring that controls are being complied with and their systems continue to operate effectively
  • implementing new controls to reduce the risk of similar fraud occurring where frauds have taken place
  • contacting the Fraud Response Co-ordinator, in line with Section 5 above, when suspicions of fraud are brought to their attention (managers should undertake some preliminary work to establish relevant facts)

Employees

All employees are responsible for:

  • acting with propriety in the use of official resources and the handling and use of public funds, whether they are involved with cash or payments systems, receipts or dealing with suppliers
  • conducting themselves in accordance with their terms and conditions of employment, VisitScotland’s policies and the values of the organisation
  • observing all current guidance contained in our various policies (details on the Hub) and the procedures relevant to the job role. This is particularly relevant to those who are buying goods and services, incurring travel and subsistence expenses, offering or accepting gifts or hospitality, and when using our IT systems
  • being alert to the possibility that unusual events or transactions could be indicators of fraud
  • reporting details immediately through the appropriate channel if they suspect that a fraud has been committed or see any suspicious acts or events
  • co-operating fully with whoever is conducting internal checks or reviews or fraud investigations

7. The provision and acceptance of gifts and hospitality

Working relationships may bring employees into contact with outside organisations where it is normal business practice or social convention to offer hospitality, and sometimes gifts. Offers of this kind can place employees in a difficult position. 

Full guidance for employees on the provision and acceptance of gifts and hospitality is covered in our Gifts and Hospitality Policy.

Employees can also seek direct guidance from directors and chief officers, as well as those in governance roles, for example, Head of Financial Services, Head of Legal or Risk and Governance Manager.

8. Notification and reporting

Any instance of suspected fraud should be reported to the Fraud Response Co-ordinator immediately.

Details of losses due to fraud or theft must be submitted to the Head of Financial Services for recording correctly as a loss or write-off in the financial statements.

For any instance of fraud, an incident report will be prepared and submitted to the Audit and Risk Committee for reporting to the Board and the Accountable Officer.

All instances of external fraud will be reported to Police Scotland. VisitScotland reserves the right to report instances of internal fraud to Police Scotland, with the Accountable Officer reviewing this position on a case-by-case basis.

The Head of Financial Services provides an annual report to the Audit and Risk Committee, VisitScotland Board, Scottish Government, Accountable Officer and external auditors detailing all instances of fraud detected during the year.

9. Conclusion

VisitScotland will not accept any level of fraud, and any case will be thoroughly investigated and dealt with appropriately.

Statement from the Board on the prevention of fraud, bribery, and tax evasion

Published August 2026

Other things you might like