03 July 2026
OECD ¦ Evaluating, Updating and Monitoring Anti‑Fraud Strategies: A Methodology
From fraud detection to financial crime disruption: building anti-fraud strategies that follow the money
Fraud is no longer adequately addressed through isolated controls, annual compliance statements or lists of completed activities. The scale, speed and organisation of fraudulent conduct increasingly require public institutions to treat anti-fraud policy as a continuous financial crime function – one that identifies vulnerabilities, detects suspicious activity, supports investigation, enables sanctions and recovers criminal proceeds.
This approach matters particularly where fraud affects public funds. Fraud against national or European budgets can generate substantial illicit proceeds, involve organised criminal groups and overlap with corruption, money laundering, tax offences, procurement manipulation and identity crime. A strategy that measures only the number of trainings delivered or procedures adopted may therefore appear successful while failing to reduce losses, disrupt criminal networks or prevent the integration of illicit funds into the legitimate economy.
Fraud as a predicate offence and source of illicit proceeds
The relationship between fraud and money laundering should be central to public-sector anti-fraud planning. Fraud is frequently the predicate offence that creates the proceeds later concealed, transferred, converted or invested through the financial system. Public grants obtained through false statements, procurement funds diverted through collusion, fraudulent VAT refund claims and misapplied subsidies can all generate assets requiring laundering.
Under the European framework protecting the Union’s financial interests, fraud includes the use of false, incorrect or incomplete documents, the deliberate omission of information and the misapplication of funds or legally obtained benefits. These acts may affect expenditure or revenue, including cross-border VAT revenue. In practical terms, the underlying conduct may involve obtaining public money through deception, retaining funds without entitlement or presenting legitimate transactions in a way that conceals non-payment or an unlawful refund.
The predicate-offence analysis should not end when the fraudulent payment is identified. Authorities should ask what happened to the funds afterwards. Were they moved through accounts controlled by related companies? Were payments routed through intermediaries or shell entities? Were proceeds used to acquire real estate, luxury goods or digital assets? Were false invoices created to disguise transfers? Did the beneficiaries of the fraud differ from the persons who received the money?
These questions connect anti-fraud controls with anti-money laundering systems, financial intelligence, asset tracing and confiscation. They also help authorities move from an administrative view of irregularity to a financial crime view of harm, intent, beneficiaries and proceeds.
A strategy must explain how change will occur
Effective anti-fraud strategies begin with a structured assessment of the problem. Authorities need reliable information about where fraud may occur, how controls can fail, which actors are exposed and what the financial and non-financial consequences may be. Risk assessments should cover both expenditure and revenue, including grants, procurement, subsidies, customs, taxation and other public income streams.
The strategy should then set a limited number of clear objectives covering the full anti-fraud cycle. Prevention, detection, investigation, prosecution, sanctions, recovery and institutional co-operation should not operate as disconnected workstreams. A preventive control that identifies a conflict of interest, for example, should connect to procedures for reviewing the transaction, referring suspected criminal conduct and tracing any resulting benefit.
This causal structure is often expressed through a results chain or theory of change. It should show how resources and activities are expected to produce outputs, outcomes and long-term impact. Training investigators is an output. Improved investigative capability is an outcome. More timely and better substantiated fraud investigations, followed by effective asset recovery, represent a more meaningful result.
Without this logic, strategies tend to confuse activity with achievement. The existence of a new procedure does not demonstrate that staff use it. The number of risk alerts does not show that suspicious cases are identified accurately. The number of referrals does not establish that investigations are effective. Measures must be connected to observable changes in behaviour, controls, enforcement and financial loss.
Measuring what matters: from activity to outcome
Monitoring systems commonly focus on whether an activity has been completed. That information remains useful, but it is not enough. A credible framework should distinguish between inputs, outputs, outcomes and impact.
Inputs include staff, funding, time and technology. Outputs include completed training, adopted procedures, risk assessments, data tools and awareness campaigns. Outcomes concern changes in institutional practice and behaviour, such as improved risk management, wider use of automated screening, better-quality irregularity reports, stronger whistleblower protection and more effective referrals to investigative authorities. Impact concerns broader changes, including reduced estimated fraud losses, greater recovery of proceeds, stronger deterrence and increased confidence in anti-fraud institutions.
Money laundering indicators should be incorporated into this structure. Relevant measures may include the proportion of suspected fraud cases referred for financial investigation, the number of cases involving proceeds tracing, the value of assets frozen or restrained, the use of financial intelligence in investigations, the time between detection of the predicate offence and identification of related assets, and the proportion of identified losses ultimately recovered.
The framework should also track the quality of outcomes. A rise in reported fraud may indicate worsening conduct, but it may equally show improved detection, more trusted reporting channels or stronger institutional willingness to act. A fall in reports may reflect reduced fraud, but it may also result from fear of retaliation, inaccessible reporting systems or declining confidence in enforcement.
For that reason, no single indicator should determine performance. Reported cases should be considered alongside detection rates, investigation outcomes, prosecution results, sanctions, recovery figures, asset tracing and qualitative evidence from investigators, prosecutors, fund managers and affected beneficiaries.
Establishing the financial scale of fraud
Authorities cannot evaluate whether an anti-fraud measure works unless they have a reasonable baseline. Known losses are important but incomplete because fraud is hidden and detection depends on the strength of controls. Recorded cases may therefore represent only part of the underlying problem.
Fraud loss measurement can help estimate the level of fraud and error in a programme or function. A sound exercise identifies high-risk areas, reviews residual risks, selects a representative sample, tests transactions using consistent classifications and extrapolates the results with appropriate confidence intervals. The resulting estimate can inform the design of controls, investigation priorities and resource allocation.
Where a full loss measurement exercise is not feasible, authorities can use historical detection data, comparable programmes, average losses per case and risk assessments to develop a provisional baseline. The methodology should be applied consistently over time. Otherwise, an apparent reduction in losses may simply reflect a change in classification, reporting practice or sampling method.
Financial estimates should also include the wider cost of fraud. Direct losses may be accompanied by investigation and litigation costs, administrative disruption, damage to legitimate businesses, harm to beneficiaries and reduced confidence in public institutions. Money laundering can increase these costs by moving proceeds across jurisdictions and placing assets beyond immediate recovery.
Evaluation should test causation, not merely compliance
Monitoring provides regular information about implementation. Evaluation asks a different question: whether the strategy produced the desired change and why.
A robust evaluation should examine relevance, coherence, effectiveness, efficiency, impact and sustainability. It should consider whether the strategy remains aligned with current fraud risks, whether its measures complement anti-corruption and anti-money laundering policies, whether resources were used proportionately, and whether results are likely to survive changes in personnel, funding or political leadership.
Evaluators should also consider causation. A reduction in fraud losses cannot automatically be attributed to a new control if economic conditions, enforcement activity, market changes or unrelated reforms may have influenced the result. Where practical, authorities can use before-and-after comparisons, comparison groups, difference-in-differences analysis, statistical matching, regression methods or controlled trials. The appropriate method will depend on the intervention, data and available resources.
In financial crime work, evaluation should examine whether controls disrupted the underlying scheme and the movement of proceeds. For example, an automated procurement screening tool should not be judged solely by the number of alerts generated. Its value depends on whether alerts are assessed, whether genuine risks are escalated, whether investigations are opened, whether losses are prevented and whether the proceeds of completed fraud are traced and recovered.
Return on investment needs careful interpretation
Calculating the return on investment of anti-fraud measures can support decisions about staffing, technology and investigative capacity. The basic analysis compares the cost of an intervention with the losses prevented, recovered or otherwise avoided.
This can be useful for comparing measures such as data analytics, staff training, identity controls, transaction testing and enhanced supervision. However, a financial ratio cannot capture every relevant result. Improved public confidence, stronger institutional capability, greater deterrence and better co-operation may be critical even where their value cannot be expressed precisely in monetary terms.
ROI should therefore be presented with its assumptions, time horizon and uncertainty. Authorities should identify the value at risk, the probability of the risk occurring, the expected effect of the intervention and the costs of implementation. They should also avoid treating estimated prevented losses as equivalent to recovered criminal proceeds. Prevention, detection, restraint, confiscation and recovery are related but distinct outcomes.
Governance determines whether information becomes action
A central co-ordinating function is essential where multiple bodies manage public funds and respond to fraud. In the European Union, this role is often associated with the Anti-Fraud Coordination Service, although the precise institutional model differs between countries.
The central body should consolidate information from managing authorities, audit bodies, revenue administrations, law enforcement, prosecutors and other relevant institutions. It should validate implementation data, identify cross-cutting risks, prepare monitoring and evaluation reports and support updates to the strategy and action plan.
Operational ownership should remain with the institutions responsible for day-to-day controls and enforcement. Each participating body should designate a focal point, maintain reliable records and report against agreed indicators. Clear mandates and information-sharing arrangements are particularly important where administrative irregularities may develop into criminal fraud or money laundering investigations.
Independent validation can reduce the risk of overstatement by implementing agencies. It may be conducted by a central body, another public institution, an external evaluator or a suitably qualified civil society organisation. Independence is not a substitute for operational knowledge, so the strongest arrangements combine external challenge with access to internal expertise.
Data quality and information-sharing are financial crime controls
A monitoring framework is only as reliable as the data supporting it. Data should be complete, accurate, timely, traceable and capable of being linked across systems. Technical connectivity alone is insufficient if institutions use inconsistent definitions or cannot interpret the information exchanged.
For fraud and money laundering purposes, useful data sources may include irregularity registers, procurement records, company and beneficial ownership information, tax and customs data, audit findings, law enforcement records, prosecution statistics, asset recovery records, whistleblower reports and financial intelligence. Access must comply with applicable privacy, confidentiality and due-process requirements, but data protection should not become a reason for preventing lawful and necessary co-operation.
Authorities should pay close attention to the chain from alert to action. A risk flag has limited value if it cannot be linked to a transaction, entity, beneficial owner, bank account, investigative referral and final outcome. Case management systems should preserve an audit trail showing who reviewed the information, what decision was taken and why.
Updating strategies as risks change
Fraud strategies should be treated as living frameworks rather than fixed policy statements. New funding instruments, regulatory changes, digital platforms, artificial intelligence, cross-border schemes and organised crime methods can quickly make existing controls inadequate.
Updates should be triggered by evidence. Relevant questions include whether new fraud risks have emerged, whether existing risks have changed, whether legislation or institutional mandates have shifted, whether objectives remain realistic and whether indicators still measure meaningful change. The review should also identify obsolete measures, duplicated controls, missing implementation steps and persistent delays.
For the action plan, an update may involve adding measures, reallocating resources, changing responsible institutions, revising deadlines or replacing weak indicators. At the strategic level, it may require new objectives addressing proceeds tracing, asset recovery, financial investigation, beneficial ownership transparency or co-operation between administrative and criminal justice authorities.
The results of monitoring and evaluation should be linked to explicit management decisions. Recommendations should have responsible owners, deadlines and follow-up arrangements. Later reviews should establish whether recommendations were implemented and whether they produced the intended effect.
Communication must support trust without normalising fraud
Public reporting strengthens accountability, but communication requires care. Publishing the status of measures, indicators, methodology and limitations allows citizens, businesses, civil society and oversight bodies to assess progress. Accessible reporting channels and clear information about whistleblower protection can also improve detection.
Messages should avoid suggesting that fraud is universal or impossible to control. Overstating the prevalence of fraud may normalise the conduct, discourage reporting or undermine confidence in institutions. Communication should instead explain what risks exist, how authorities respond, where suspicions can be reported and what safeguards protect those who provide information.
The same principle applies to negative results. Delays, weak recovery rates or poor-quality investigations should be reported candidly, but framed as issues requiring corrective action rather than as reasons to conceal data. Transparency about limitations can strengthen credibility when it is accompanied by specific remedial measures.
A stronger standard for anti-fraud performance
The central test for an anti-fraud strategy is not whether institutions produced plans, held meetings or completed forms. It is whether the system became better at preventing fraudulent payments, detecting suspicious conduct, investigating the predicate offence, identifying and restraining illicit proceeds, applying proportionate sanctions and recovering public funds.
That standard requires continuous monitoring, periodic independent evaluation, reliable financial data and a direct link between evidence and decision making. It also requires anti-fraud, anti-corruption, anti-money laundering, tax, procurement, audit and criminal justice authorities to work from a shared understanding of risk.
When these elements are combined, anti-fraud policy becomes more than an administrative reporting exercise. It becomes a practical framework for reducing financial losses, disrupting the laundering of fraud proceeds and strengthening the integrity of public spending.
Dive deeper
- OECD ¦ Evaluating, Updating and Monitoring Anti‑Fraud Strategies: A Methodology ¦ Link