Fraud risk management
Report 6: 2017–18. Tabled date: 2018-02-15. 3 recommendations published as HTML.
Tabled Report 6: 2017–18
- Tabled date
- 2018-02-15
- Report year
- 2017-18
Entities audited
Not identified in the published HTML audit scope.
Recommendations
QAO's text Addressed to: all public sector agencies
self-assess against the better practices listed in this report to improve fraud control policies and plans where required, and make sure accountabilities and responsibilities for fraud control are clear.
QAO's text Addressed to: integrate fraud risk management systems and procedures within existing enterprise risk management frameworks. The integrated framework
integrate fraud risk management systems and procedures within existing enterprise risk management frameworks.
The integrated framework should include the requirement to:
- conduct regular fraud risk assessments at the entity and detailed level, to identify current and emerging risks
- record fraud risks in a fraud risk register or using a fraud risk category in existing registers
- train and provide guidance to employees on how to conduct fraud risk assessments, and how to effectively design, implement and monitor controls to mitigate risks
- ensure control owners regularly assess and report on the operational effectiveness of fraud controls
- document controls and treatments to mitigate fraud risks that are clear and measurable, with a defined timeframe and assigned to a responsible officer.
QAO's text Addressed to: monitor through their governance forums, their agencies' exposure to fraud risk and the effectiveness of their internal controls to mitigate any risks. Key governance committees, including boards and audit and risk committees
monitor through their governance forums, their agencies' exposure to fraud risk and the effectiveness of their internal controls to mitigate any risks.
Key governance committees, including boards and audit and risk committees should:
- review whether the agency has a comprehensive enterprise risk management framework in place, to effectively identify and manage risks, including fraud risks
- ensure the agency has appropriate processes or systems to capture and assess fraud risks
- review reports on fraud risks, and fraud incidents (that occur both within the agency and the broader public sector), considering how reported allegations and confirmed incidents may change identified fraud risks.
Authoritative report — Queensland Audit Office
Source: Queensland Audit Office, CC BY 4.0
Catalogue snapshot 2026-10-09
© The State of Queensland (Queensland Audit Office) 2026
Report metadata arranged into a catalogue. Recommendations reproduce QAO's words with HTML formatting simplified; no model summaries. Responses and PDF bodies are excluded.
Report pages checked individually. Recommendations and body-derived entities are withheld for licence exceptions. Images, logos and multimedia are excluded.
No endorsement by the State of Queensland or Queensland Audit Office is implied.