A corporate ethics programme can look complete on paper and still fail to prevent fraud. The decisive question is whether it changes incentives, exposes misconduct early and produces consistent consequences.
Policies are not controls
A code of conduct describes expected behaviour; it does not prove that approvals, segregation of duties, payment controls or reconciliations work. Investigators should map the organisation’s actual fraud risks and test the controls intended to reduce each one. Generic annual training is weak evidence if the company ignored recurring risks in sales, procurement, expenses or third-party payments.
The US Department of Justice’s Evaluation of Corporate Compliance Programs asks whether a programme is well designed, applied earnestly and working in practice. That structure is useful beyond criminal enforcement because it directs attention to evidence rather than slogans.
Leadership and incentives must align
“Tone at the top” fails when revenue targets, bonuses or promotion decisions reward conduct the policy forbids. Review board minutes, management messages, compensation rules, exception approvals and disciplinary records. Middle managers matter especially: employees often respond more directly to the supervisor who controls their workload and career than to a chief executive’s annual statement.
Governance also weakens at subsidiaries, joint ventures and outsourced operations. This is why examining control failures at group edges can reveal gaps that headquarters reporting conceals. Broader commentary on investor confidence and good governance provides useful context, but company-specific conclusions still require primary records.
Reporting channels must lead to action
A hotline is ineffective if workers distrust anonymity, fear retaliation or never learn what happens after a report. Test channel availability by location and language, response times, triage criteria, case ownership and retaliation monitoring. A credible programme protects the evidential value of an anonymous whistleblower tip while independently corroborating it.
Investigations should have clear protocols for conflicts, legal preservation, interviews, access to systems and escalation to the board. Compare similar cases: unexplained differences in discipline between senior producers and junior staff are a strong warning that the programme is performative.
Third parties and transactions create blind spots
Agents, distributors, consultants and acquisition targets can import risks the company would reject internally. Examine risk-based due diligence, beneficial ownership, contract clauses, payment patterns and continuing monitoring. After an acquisition, confirm that finance systems, reporting channels and control testing were actually integrated rather than merely scheduled.
The OECD anti-corruption compliance handbook emphasises practical internal controls, ethics and compliance measures. It is a useful benchmark, but investigators should also check the laws and regulatory expectations that apply in the relevant jurisdiction.
Measure outcomes, not activity
Training completion rates and policy acknowledgements are inputs. More revealing measures include substantiation trends, reporting delays, repeat control failures, override frequency, remediation deadlines, disciplinary consistency and recovery of improper payments. Data analysis should test transactions continuously and explain anomalies rather than simply generate alerts.
No programme can guarantee that fraud never occurs. Failure is better shown when risks were foreseeable, warnings were suppressed, controls were bypassed without review or remediation was repeatedly delayed. A fair assessment therefore distinguishes an isolated evasion from a system that rewarded, tolerated or concealed misconduct.