Existing clients

Log in to your client extranet for free matter information, know-how and documents.

Client extranet portal

Staff

Mills & Reeve system for employees.

Staff Login
02 Oct 2026
4 minutes read

Who owns fraud risk? A governance question hiding in plain sight

Who should own fraud risk? The short answer: The board and senior leadership should own the overall risk. Day-to-day responsibilities can sit across legal, compliance, finance, internal audit and operations. The general counsel’s role is to connect those teams, identify gaps and help the board make informed decisions.

Fraud is often treated as something for legal or compliance to deal with after an incident. In reality, it can arise through payments, systems, suppliers, data and operational processes. That makes it a business risk, not simply a legal issue.

What general counsel need to know

  1. There should be a named senior owner for fraud risk.

  2. Each team should know what it is responsible for before, during and after an incident.

  3. The board should receive useful information about risks, controls, incidents and remediation.

  4. Legal can coordinate the response without taking ownership of every operational control.

  5. The right model will depend on the organisation’s size, sector and risk profile.

Why does ownership become unclear?

Different teams see different parts of the risk. Finance manages payments. Operations runs the relevant processes. Compliance develops policies. Internal audit tests controls. Legal advises on investigations, reporting and disputes.

The problem is not a lack of activity. It is that no one may have a clear view across the whole organisation. This can lead to duplicated work, missed warning signs and uncertainty about who makes urgent decisions.

Why does this matter now?

Prevention is under greater scrutiny

The UK failure to prevent fraud offence has increased the focus on proportionate prevention measures. It applies to large organisations, but its principles can also provide a useful benchmark for smaller businesses.

Fraud cuts across the business

Modern fraud may involve technology, employees, suppliers, payment systems and several jurisdictions. One team is unlikely to have all the information or authority needed to manage it alone.

Boards may need to explain the organisation’s approach

After a serious incident, the board may be asked who was accountable, what controls were in place, whether they were tested and how warning signs were handled.

What does a workable model look like?

An organisation does not necessarily need a new fraud function. It does need:

  • A named executive or board-level owner.

  • Clear responsibilities for prevention, detection, escalation, investigation, recovery and remediation.

  • An agreed route for urgent decisions and notifications.

  • Regular board or committee reporting.

  • Testing of controls in practice.

  • Review after incidents or significant business change.

Practical example

If supplier bank details are fraudulently changed, finance, IT, procurement, legal, insurers and banks may all need to act. The organisation should already know who can stop payments, preserve data, contact the banks, instruct advisers and brief the board.

What should general counsel do?

General counsel can:

  • Check that responsibilities and escalation routes are clear.

  • Bring together legal, regulatory, contractual and operational issues.

  • Help structure investigations and manage privilege carefully.

  • Advise on reporting, insurance and recovery options.

  • Give the board a concise view of the risks and decisions required.

This does not mean legal should run every control. The aim is to make sure the organisation has a coordinated and defensible approach.

Questions to ask now

  1. Who is the senior owner of fraud risk?

  2. Who leads if an incident happens outside normal working hours?

  3. What information reaches the board and how often?

  4. When were the main fraud risks and controls last tested?

  5. Can the organisation show what decisions were made and why?

Frequently asked questions

  • Should the general counsel own fraud risk? Usually not alone. Overall ownership normally sits with senior management or the board, while relevant business teams own the operational controls. General counsel can provide oversight and coordination.

  • Does every organisation need a dedicated fraud team? No. The structure should be proportionate. Clear accountability and effective coordination matter more than the name of the team.

  • How often should the arrangements be reviewed? They should be reviewed regularly and after material incidents, acquisitions, system changes, new products or significant changes in risk.

  • What evidence shows active ownership? Examples include an approved risk assessment, named responsibilities, training, control testing, incident exercises, board reporting and records of remediation.

Final thoughts

If a significant fraud happened tomorrow, could the organisation quickly explain who was responsible, what controls were in place and how the board had tested them? If not, ownership may need to be clarified now.

For more information or to discuss any of the points in this article, please get in touch with our fraud and investigatory team.

Our content explained

Every piece of content we create is correct on the date it’s published but please don’t rely on it as legal advice. If you’d like to speak to us about your own legal requirements, please contact one of our expert lawyers.