3. Definition of fraud
The term "fraud" is used to describe such acts as deception, bribery, forgery, extortion, theft, conspiracy, embezzlement, misappropriation, false representation, concealment of material facts, financial or professional malpractice and collusion.
Fraud is usually used to describe depriving someone of something by deceit, which might either be straightforward theft, misuse of funds or other resources, or more complicated crimes like false accounting and the supply of false information.
This also extends to the use of VisitScotland’s name or other details, whereby another person or body attempts to pass themselves off as VisitScotland.
It also applies when an individual or body attempts to present themselves as someone they are not, for example, falsely represents themselves as a legitimate supplier.
Computer fraud is where IT equipment (including the use of AI) has been used to manipulate programs or data dishonestly (for example, by altering, substituting or destroying records, or creating spurious records), or where the use of an IT system (including the use of AI) was a material factor in the perpetration of fraud.
Theft of data or fraudulent use of computer time and resources is included in this definition.
Employees are directed to the Data Protection Policy, and the IT Acceptable Use Policy, which prohibit the use of USB “flash drives” for any extraction of personal or business sensitive data and the Generative AI (Artificial Intelligence) Policy.
Historically, most internal fraud in organisations such as VisitScotland has been linked to claims for travel and subsistence and overtime, recording of cash receipts, irregularities in procurement procedures and the abuse of flexible working hours.
Examples of external fraud include providing false information in applications for grants or other forms of assistance, suppliers offering bribes or inducements and submitting bogus invoices.
VisitScotland has experienced attempts in the past of external fraud whereby individuals have presented themselves as legitimate suppliers to secure payment from VisitScotland or where individuals have presented themselves to a third party as “VisitScotland”.
In all cases VisitScotland will investigate and take relevant action to avoid the loss of VisitScotland monies and also protect the reputation of VisitScotland.
The Bribery Act 2010 requires organisations to demonstrate that they have “adequate procedures” in place to prevent bribery.
This topic is addressed in VisitScotland’s separate over-arching Anti-Bribery and Corruption Policy, which embraces a number of other more detailed policies.
VisitScotland have identified the following business-as-usual activities as particular risks for our organisation in respect of fraud:
- Making payment to suppliers.
- Making payment to contractors.
- Making payment to employees.
- Making payments in cash on familiarisation (“Fam”) trips or other similar activities.