AI and fraud prevention: staying ahead of emerging risks
AI and the changing fraud threat landscape
As artificial intelligence (AI) becomes increasingly integrated into our daily work, more organisations are embracing emerging AI technologies to improve efficiency, automate repetitive tasks and deliver more personalised services. While these technologies offer significant benefits, their use in day-to-day tasks could represent a change in your entity's activities that should trigger a review of your enterprise fraud risk assessment. You may need to consider how your use of AI tools could create new opportunities for fraudsters seeking to exploit systems, processes and trust.
The emergence of AI-enabled fraud also presents new challenges for governments and organisations worldwide. Sophisticated tools can be used to create convincing fake identities (deepfakes), manipulate documents, automate scams and generate misleading information at scale. The foundations of effective fraud and corruption prevention remain unchanged, but the specifics of how your entity understands and mitigates its fraud risks may need to rapidly adapt to respond to these emerging threats.
The fundamentals still matter
Protecting valuable information, assets and services continues to rely on understanding risks and implementing robust controls, checks and processes. Fundamental practices such as confirming and authenticating identities, verifying information provided by applicants, and undertaking quality assurance checks on decisions and outcomes remain critical safeguards. These measures help ensure organisations can prevent, detect and respond to fraud risks, however those risks are enabled.
The Commonwealth Fraud and Corruption Control Framework is technology-neutral and requires entities to identify, assess and manage fraud and corruption risks, including emerging threats such as those posed by AI. Similarly, relevant offences under Chapter 7 of the Criminal Code Act 1995 (Cth) are technology-neutral. In other words: fraud is fraud, no matter how it is perpetrated.
Using AI to strengthen fraud prevention
AI is not only a source of risk. It also presents significant opportunities to enhance fraud prevention capabilities. The Commonwealth Fraud Prevention Centre is developing guidance on the use of AI-enabled tools to strengthen fraud and corruption risk management activities, from undertaking risk assessments to identifying vulnerabilities during policy design and program development. Stayed tuned for further information about this exciting work!
Beyond supporting fraud risk assessments and prevention activities, AI offers opportunities to enhance the way Commonwealth entities detect, analyse and respond to fraud risks. AI-enabled tools can help officials identify unusual patterns, anomalies and emerging fraud indicators across large and complex datasets that would otherwise be difficult to detect through traditional methods alone. Over time, these capabilities may support more targeted fraud control planning, strengthen monitoring and assurance activities, and help entities identify vulnerabilities earlier in the policy, program and service delivery lifecycle.
Practical steps counter-fraud officials can take now
Under the Commonwealth Fraud and Corruption Control Framework, Commonwealth entities must conduct fraud and corruption risk assessments when substantial changes occur to their structure, functions or activities. The adoption of AI may constitute such a change and should prompt you to consider whether existing assessments remain suitable and whether new or emerging risks need to be identified, assessed and treated.
When assessing AI-related risks, officials should consider both how their entity uses AI and how malicious actors may use it. This includes examining the impact of AI use on existing controls, decision-making, information management and assurance processes, as well as emerging AI-enabled fraud threats targeting programs, services, systems and staff.
Do not undertake fraud and corruption risk assessments in isolation. To effectively identify and treat AI-related fraud risks, you need to collaborate across relevant business areas, including program and business owners, ICT and cyber security teams, data specialists, privacy and legal advisers, procurement and contract managers, internal audit and risk functions, and integrity, security and human resources teams.
As AI capabilities continue to evolve, it will be essential to maintain strong fraud and corruption controls while responsibly embracing innovation. By combining proven risk management practices with modern technology, Australian Government entities can strengthen resilience, protect public resources and remain one step ahead of emerging fraud threats.