← Governance

Fraud and Risk Management Policy

How we prevent, detect and respond to fraud, and who to report it to.

Introduction

Just like commercial organisations, not-for-profit organisations may be subject to fraudulent activity and must therefore implement effective prevention strategies to minimise legal and financial exposure.

Purpose

The purpose of this Policy is to:

  1. Ensure that all parties are aware of their responsibilities regarding the identification and prevention of fraudulent activity.
  2. Ensure that staff/volunteers/contractors understand who to report to in the event that they suspect fraudulent activity.
  3. Provide a step-by-step guide to respond to an allegation regarding fraudulent activity.
  4. Express a clear statement to staff/volunteers/contractors forbidding fraudulent activity for the benefit of the organisation.

Policy

  1. The Company will not tolerate fraud in any aspect of its operations.

  2. Australian Charities and Not-for-profits Commission (ACNC)

    The Board acknowledges its obligations under the Australian Charities and Not‑for‑profits Commission Act 2012 and Governance Standard 5 to exercise active oversight of fraud and corruption risks. This includes:

    • Ensuring that appropriate prevention, detection, and response controls are in place.
    • Regularly reviewing the organisation's fraud and corruption risk profile and control framework.
    • Receiving reports on fraud risk management activities at least annually.
  3. Whistleblower Protections

    The organisation complies with the Corporations Act 2001 and Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019 as they apply to eligible not‑for‑profit entities. As such:

    • Any person making a report of suspected fraud or corruption in good faith is protected from victimisation, dismissal, or other disadvantage.
    • Whistleblower identities will be kept confidential in accordance with the law, except where disclosure is authorised or legally required. Anonymous reports are also accepted where legally permissible.
    • Reports may be made to the CEO, Company Secretary, Chair of the Board, or an alternative authorised recipient as outlined in the organisation's Whistleblower Policy.
  4. Privacy Act Compliance

    All investigations involving personal information will comply with the Privacy Act 1988 (as amended in 2023–2025 reforms). This includes:

    • Storing information securely and limiting access to authorised personnel only.
    • Meeting mandatory notification requirements for any eligible data breach.
    • Ensuring that any cross‑border transfer of personal information meets applicable Australian privacy requirements.
  5. The Company will investigate any suspected acts of fraud, misappropriation or other similar irregularity. An objective and impartial investigation, as deemed necessary, will be conducted regardless of the position, title, length of service or relationship with the organisation of any party who might be the subject of such investigation.

  6. Any fraud shall constitute grounds for dismissal. Any serious case of fraud, whether suspected or proven, shall be reported to the relevant and appropriate authorities such as the police and the ombudsman.

  7. Any person who suspects the commission of a fraud, related to the operations of the Company, is required to immediately report it to a manager / appropriate person in authority within the Company. Any person reporting a fraud, or a suspected fraud, shall not be penalised for raising a concern of this nature.

  8. Fraud risks extend beyond traditional financial misconduct to include a range of technology‑enabled threats. The organisation acknowledges that cyber fraud and digital scams present significant risks to not‑for‑profit operations, including:

    • Phishing and email impersonation scams aimed at diverting funds or obtaining sensitive information.
    • Ransomware attacks that may encrypt organisational data and demand payment for release.
    • Payroll and supplier payment diversion fraud involving unauthorised changes to payment details.
    • Online donation fraud through fake fundraising pages or unauthorised transactions.

The organisation will maintain appropriate controls, regular staff awareness training, and incident response procedures to mitigate these risks.

Appendix

These sit alongside this policy but are not published. They are for our team, and you will need access to open them.

Approved by
Board of Good Ancestors Policy Ltd
Date approved
4 August 2026
Version
1.0
Owner
Company Secretary

This policy names offices rather than people. Who currently holds each one is listed on our org chart.