UK companies are more likely to experience internal fraud than the global average, with internal culture failing to prioritise the risks
In the last 12 months, 38% of UK businesses experienced internal fraud, compared with a global average of just 27%. The only region which had a higher incidence of internal fraud was sub-Saharan Africa at 44%, according to the Kroll annual global fraud and risk report.
Despite performing worse than other competitors, nearly one in four (38%) UK business leaders did not view fraud as a risk priority, compared to a global average of 34%. The survey polled around 600 senior executives with responsibility for risk management strategies in 13 countries.
The most prevalent incident affecting UK firms in the last 12 months was reputational damage due to third-party relationships, suffered by 42% of all UK businesses – 13% higher than the global average of 29%.
The report suggested that one of the reasons for the frequency of fraud in UK companies was down to the company culture with senior management not taking the issue seriously enough.
Nearly a third (30%) of UK respondents said that there was no clear message from the top of their organisations that integrity, compliance and accountability were important (versus 22% globally). Also, in the UK 20% of incidents were reported by whistleblowers - 7% higher than the global average - indicating that ‘more work needed to be done on reinforcing key cultural norms, as whistleblowing often reflects low confidence in traditional remediation channels’.
Almost four in 10 (38%) businesses also suffered from leaks of internal information, roughly in line with the global average (39%). Risks arising from adversarial social media activity was also high on the business agenda, with nearly a third (32%) of businesses experiencing a major incident over the last year, five percentage points higher than the global average (27%).
The research found more than three quarters (77%) of business leaders said that data theft was a priority, the highest of any risk, despite the fact that only 32% of companies actually suffered an incident of this type.
Kroll’s analysis suggested this could be explained by the recent implementation of the General Data Protection Regulation (GDPR), which has made businesses much more concerned about data privacy issues.
This could also be behind cyber security measures registering as the most effective risk detection mechanism, with 77% of respondents agreeing that their cyber detection mechanisms are effective as businesses have increased investment to help mitigate cyber risk.
Technology looks set to remain an issue, as 68% of UK business leaders see disruptions caused by AI or other technologies as a significant future risk. Two thirds (66%) cited large-scale, coordinated cyberattacks as a future risk that will affect their business. This includes cryptocurrency, with nearly 89% of UK business leaders reporting involvement with the technology in at least some way.
Neil Kirton, managing director at Kroll, said: ‘The range of risks facing UK businesses has widened significantly in recent years, with new global regulations, more complex supply chains reaching around the world and ever-evolving cyber threats.
‘The UK has been particularly vulnerable to internal fraud and reputational damage from third-party relationships, and other threats continue to rise.’
Kroll is a division of Duff & Phelps.