FRAUD MANAGEMENT POLICY
Free From Fees Pty. Ltd.
FRAUD MANAGEMENT POLICY.
1. Objectives:
The objectives of this policy are to:
a) uphold the values of The Company by acting in good faith, ethically and in the best interests of The Company, and by promoting a culture of honesty, integrity and professionalism;
b) establish a comprehensive framework for the prevention, detection, reporting, investigation and response to internal fraud, external fraud, corruption and bribery;
c) provide guidance about conduct that constitutes internal fraud, external fraud and corruption so that persons working for or on behalf of The Company can recognise and respond appropriately to such conduct;
d) outline the responsibilities of Board members, management, employees, contractors and other relevant persons in preventing fraud and corruption and responding to suspected or detected conduct;
e) protect The Company, its retailers, consumers, personnel, service providers and other stakeholders from financial loss, operational disruption, legal or regulatory exposure and reputational harm arising from fraud;
f) provide clear avenues for reporting current or past instances of suspected fraud, attempted fraud, corruption or bribery;
g) support compliance with The Company’s AML/CTF Program, applicable laws, regulatory obligations and contractual requirements; and
h) outline the potential consequences of fraud, corruption and related misconduct.
2. Scope:
2.1 This policy applies to:
(a) all Board members, appointed managers and employees of The Company;
(b) all of The Company’s interactions and business dealings with retailers, consumers, banks, payment service providers, technology providers and other third parties;
(c) all individuals and organisations contractually required to comply with this policy or with related fraud control requirements; and
(d) all systems, products, services, transactions, payment arrangements and business processes operated by or on behalf of The Company.
2.2 All other individuals engaged in activities reasonably connected with The Company are expected to conduct themselves consistently with this policy, including:
(a) contractors;
(b) consultants;
(c) agents and representatives;
(d) retailers and their personnel;
(e) outsourced service providers and technology providers; and
(f) any other person who has access to The Company’s information, systems, funds or payment services.
2.3 This policy addresses both internal fraud and external fraud, whether attempted, suspected or completed, and whether committed independently or in collusion with another person.
3. Authority and related requirements:
3.1 This policy supports compliance with applicable Commonwealth and State laws and regulatory requirements, including obligations arising under The Company’s AML/CTF Program and relevant AUSTRAC guidance and reporting requirements.
3.2 The policy is aligned with the principles of AS 8001:2021, Fraud and Corruption Control, and should be read together with The Company’s AML/CTF Program, AML/CTF Risk Management Policy, Whistleblower Policy, Information Security and Privacy requirements, merchant onboarding procedures, transaction monitoring procedures and incident response arrangements.
3.3 Nothing in this policy limits any legal, regulatory, contractual or professional obligation to report suspected criminal conduct, suspicious matters, data breaches or other reportable events.
4. Policy:
4.1 The Company and its management are committed to preventing, detecting and responding to fraud and corruption, including internal fraud, external fraud, bribery and foreign bribery.
4.2 The Company has zero tolerance for fraud and corruption. Any suspected, attempted or completed fraud or corruption must be reported promptly and managed appropriately, proportionately and confidentially.
4.3 The Company will apply an integrated, risk-based approach to fraud and corruption control. Controls will be proportionate to the nature, scale and complexity of The Company’s operations and to the risks presented by its payment services, retailers, consumers, personnel, systems and third-party relationships.
4.4 The Company will maintain an ethical culture that supports vigilance, professional scepticism, accountability and timely reporting of fraud-related concerns without victimisation or reprisal.
Internal fraud:
4.5 Internal fraud is fraud committed by, or involving, a Board member, manager, employee, contractor, consultant, agent or other person who has an internal or trusted relationship with The Company.
4.6 Internal fraud may include, but is not limited to:
(a) theft or misappropriation of money, data, equipment or other property;
(b) falsification, concealment, alteration or destruction of records;
(c) unauthorised payments, refunds, account changes or transaction adjustments;
(d) payroll, expense, procurement or invoicing fraud;
(e) misuse of confidential information, customer information, credentials, systems or privileged access;
(f) undisclosed conflicts of interest, secret commissions, bribery or collusion;
(g) deliberately overriding, disabling or circumventing controls; and
(h) assisting, facilitating or concealing fraud committed by an external party.
External fraud:
4.7 External fraud is dishonest, deceptive or unlawful conduct committed by a person or organisation outside The Company, whether acting alone or in collusion with an insider, to obtain money, services, information or another benefit, or to cause loss or harm through misuse of The Company’s systems, services or business relationships.
4.8 External fraud risks relevant to The Company may include, but are not limited to:
(a) identity theft, identity fraud and the use of false, stolen or synthetic identities;
(b) false, misleading or fraudulent retailer or consumer applications;
(c) forged, altered or fraudulently obtained identification, business registration, bank account or onboarding documents;
(d) account takeover, credential theft, credential stuffing or unauthorised account access;
(e) phishing, smishing, vishing, impersonation, social engineering or business email compromise;
(f) unauthorised payment transactions, payment diversion or use of stolen payment credentials;
(g) QR code substitution, tampering or redirection;
(h) transaction laundering or use of a legitimate retailer account to process payments for an undisclosed, unauthorised, prohibited or illegal business;
(i) false refund requests, refund abuse, chargeback abuse or friendly fraud;
(j) use of mule accounts, compromised bank accounts or third-party accounts to receive or transfer fraud proceeds;
(k) cyber-enabled fraud, malicious software or attacks intended to manipulate transactions or obtain information;
(l) collusion between retailers, consumers, employees, contractors or other third parties; and
(m) any attempted misuse of The Company’s products, payment platform, accounts, data or settlement processes for fraudulent purposes.
Fraud prevention controls:
4.9 The Company will establish and maintain fraud prevention controls appropriate to its risk profile. These may include:
(a) Know Your Customer, Know Your Business and merchant due diligence procedures;
(b) verification of identity, business ownership, authority to act, bank account details and beneficial ownership;
(c) screening and risk assessment of retailers, consumers, personnel and relevant third parties;
(d) segregation of duties, approval limits, access controls and least-privilege system access;
(e) secure authentication, password and credential management controls;
(f) independent reconciliation of transactions, settlements, refunds, fees and bank records;
(g) controls over onboarding, changes to bank details, refunds, settlements and account administration;
(h) fraud awareness and role-specific training;
(i) contractual fraud control, notification, audit and cooperation requirements for relevant service providers and retailers;
(j) information security, cyber security, privacy and data protection controls; and
(k) periodic testing and review of fraud risks and fraud controls.
Fraud detection and monitoring:
4.10 The Company will use reasonable and proportionate methods to detect suspected internal and external fraud, including transaction monitoring, exception reporting, reconciliations, complaints, alerts from financial institutions or service providers, system and access logs, audit activity and staff observations.
4.11 Indicators of possible fraud may include:
(a) unusual transaction values, volumes, velocity, timing or geographic patterns;
(b) repeated failed onboarding or authentication attempts;
(c) duplicate or shared identities, contact details, devices, bank accounts, IP addresses or business information;
(d) rapid changes to account, settlement or bank details;
(e) abnormal refund, reversal or chargeback activity;
(f) payments inconsistent with a retailer’s stated business, expected activity or risk profile;
(g) unexplained overrides, access outside normal duties or attempts to bypass controls;
(h) inconsistencies in identification or supporting documentation;
(i) complaints or reports from consumers, retailers, banks, payment providers, law enforcement or other third parties; and
(j) any behaviour or activity that appears designed to conceal the true nature, source, destination, ownership or purpose of a transaction.
Standards and expectations:
4.12 All Board members, managers, employees, contractors and relevant personnel must:
(a) understand and comply with this policy and undertake relevant training;
(b) comply with applicable laws, regulations, codes, contractual obligations and lawful instructions;
(c) act honestly and exercise appropriate skill, care and diligence;
(d) protect The Company’s funds, information, systems, credentials, equipment and reputation;
(e) not knowingly expose The Company, a retailer or a consumer to an unacceptable fraud risk;
(f) observe high standards of integrity in financial, payment and customer matters;
(g) disclose, document and appropriately manage actual, potential or perceived conflicts of interest;
(h) not override, disable or circumvent a fraud control without documented authority; and
(i) report suspected, attempted or completed fraud or corruption at the earliest reasonable opportunity and preserve any evidence that may be relevant to an assessment or investigation.
5. Procedural principles:
Reporting:
5.1 Any Board member, manager, employee, contractor or other person who becomes aware of suspected, attempted or completed fraud or corruption should report the matter promptly to the Compliance Manager or the CEO.
5.2 Reports may arise from personnel, retailers, consumers, transaction monitoring, complaints, banks, payment providers, service providers, auditors, regulators, law enforcement agencies, cyber security monitoring or other sources.
5.3 Any report received by a supervisor, manager, director or executive must be referred promptly to the Compliance Manager. Where the report concerns the Compliance Manager, it must be referred to the CEO or the Board. Where it concerns the CEO, it must be referred to the Board.
5.4 The Company will take reasonable steps to protect the confidentiality of a person who makes a report, subject to legal and regulatory requirements and the need to investigate or respond to the matter.
5.5 Reports will be managed in accordance with applicable Commonwealth and State legislation, The Company’s Whistleblower Policy where relevant, and the principles of procedural fairness.
5.6 The Company does not tolerate victimisation or reprisal against a person who makes, proposes to make, or assists with a genuine report. Knowingly false, vexatious or frivolous reports may result in disciplinary or other action.
5.7 Where The Company becomes aware of actual or suspected significant or systemic fraud, the matter must be escalated promptly to the CEO, Compliance Manager, Chief Financial Officer (if appointed) and the Board, as appropriate.
5.8 The Compliance Manager will assess whether the circumstances give rise to obligations to report or disclose the matter to AUSTRAC, Police, another regulator, a financial institution, payment provider, insurer, affected person or another external body.
Initial containment and external fraud response:
5.9 Where external fraud is suspected, The Company may take immediate and proportionate steps to prevent further loss or misuse. Subject to applicable law, contract and procedural fairness, these steps may include:
(a) suspending or restricting an account, transaction, payment or service;
(b) delaying or withholding settlement while the matter is assessed;
(c) blocking or resetting credentials and restricting system access;
(d) seeking additional identification, verification or supporting information;
(e) preserving transaction records, logs, communications, documents and other evidence;
(f) contacting an affected bank, payment provider, retailer, consumer or service provider;
(g) attempting to recall, stop, trace or recover funds;
(h) activating information security, cyber incident, privacy or business continuity procedures; and
(i) notifying relevant authorities or external bodies where required or appropriate.
5.10 Protective action taken under clause 5.9 does not constitute a determination that fraud has occurred. It is an interim risk-control measure pending assessment or investigation.
Assessment and investigation:
5.11 Reports of fraud and corruption, including bribery, will be reviewed by the Compliance Manager or an appropriately authorised delegate in consultation with the CEO and, where appropriate, the Board.
5.12 A preliminary assessment may be undertaken to determine:
(a) the nature, credibility and seriousness of the allegation or indicator;
(b) whether immediate containment or customer protection action is required;
(c) whether the matter may involve money laundering, terrorism financing, cyber crime, a privacy or data breach, or another reportable event;
(d) whether an internal or independent investigation is required;
(e) whether external legal, forensic, accounting, cyber security or investigative expertise is required; and
(f) whether the matter should be referred to Police, AUSTRAC, another regulator, a bank, payment provider or insurer.
5.13 Investigations will be appropriately authorised, scoped and documented and will be conducted confidentially, objectively and consistently with applicable law, contractual obligations and procedural fairness.
5.14 A person who is the subject of an allegation must not direct, control or improperly influence the investigation. Actual or perceived conflicts of interest in the investigation must be disclosed and managed.
5.15 Relevant evidence must be protected from alteration, loss, destruction or unauthorised disclosure. Records should be handled in a manner that supports their integrity and potential use in disciplinary, civil, regulatory or criminal proceedings.
5.16 Outcomes of an assessment or investigation may include no further action, control improvements, disciplinary action, suspension or termination of a retailer or third-party relationship, recovery action, civil proceedings, insurance notification, regulatory reporting or referral to law enforcement.
5.17 All suspected and confirmed incidents of fraud and corruption will be recorded in a fraud incident register or equivalent Company record to support trend analysis, loss measurement, reporting, remediation and prevention of recurrence.
Disciplinary, contractual and legal action:
5.18 Any employee or other person engaged by The Company who is found to have engaged in fraud, corruption, bribery, concealment or related misconduct may face disciplinary action up to and including termination of employment or engagement.
5.19 A retailer, supplier, contractor, service provider or other external party found to have engaged in fraud may have its access restricted or terminated and may be subject to recovery action, contractual remedies, civil proceedings or referral to relevant authorities.
5.20 If criminal offences may have been committed, The Company may refer the matter to State or Federal Police or another appropriate authority. The Company will take reasonable care not to compromise a criminal or regulatory investigation and may seek legal advice or direction from the relevant authority before taking further action.
5.21 The Company may seek recovery of losses, costs, proceeds or property arising from fraud or corruption where lawful and commercially appropriate.
Post-incident review and reporting:
5.22 Following a significant fraud incident, The Company will consider whether a post-incident review is required to identify root causes, control failures, lessons learned and remedial actions.
5.23 Material fraud incidents, trends and remediation activities will be reported to the CEO and Board at a frequency and level of detail appropriate to the risk.
5.24 Remedial actions will be assigned to accountable owners, given target completion dates and monitored until closure.
6. Insurance:
6.1 The Company will maintain and periodically review the adequacy of insurance coverage relevant to internal fraud, external fraud, cyber-enabled fraud, crime, professional liability and related risks, having regard to availability, cost and The Company’s risk profile.
6.2 Suspected incidents that may give rise to an insurance claim must be notified to the insurer or broker promptly and in accordance with the applicable policy terms.
7. Training and awareness:
7.1 Personnel will receive fraud awareness training appropriate to their duties and level of fraud exposure.
7.2 Personnel with responsibilities for onboarding, payment operations, refunds, settlements, customer support, compliance, technology, finance or investigations will receive role-specific training relevant to the fraud risks they may encounter.
7.3 Training will address internal and external fraud indicators, reporting obligations, evidence preservation, social engineering, information security and the relationship between fraud and AML/CTF risk.
8. Recordkeeping and privacy:
8.1 Fraud reports, assessments, investigations, decisions, evidence and remedial actions must be documented and retained securely in accordance with applicable laws and The Company’s recordkeeping requirements.
8.2 Access to fraud-related records will be limited to persons with a legitimate need to know.
8.3 Personal information collected or used under this policy must be handled in accordance with applicable privacy obligations, subject to lawful disclosures required for investigation, reporting, recovery or enforcement purposes.
9. Definitions:
Account takeover means unauthorised access to, or control of, a legitimate retailer, consumer or other account, commonly through stolen credentials, social engineering or compromised devices.
Bribery means offering, giving, receiving or soliciting an item of value with the intention of obtaining a benefit that is not legitimately due or influencing, gaining or retaining business or a business advantage.
Business email compromise means a fraud in which email accounts or identities are compromised or impersonated to deceive a person into transferring funds, changing payment details or disclosing information.
Conflict of interest means a situation in which a person’s private, personal or financial interests conflict, or may reasonably be perceived to conflict, with their duties or responsibilities to The Company.
Corruption as defined by AS 8001:2021, is dishonest activity in which a person associated with an organisation acts contrary to the organisation’s interests and abuses a position of trust to achieve personal advantage or advantage for another person or organisation. It may include bribery, abuse of trust, misuse of resources or information, secret commissions, threats or other unethical conduct.
Detrimental action means action taken against a person in reprisal for making, proposing to make, or assisting with a report or disclosure. It may include dismissal, injury in employment, disadvantageous alteration of duties, discrimination, harassment, intimidation, psychological harm, property damage, reputational damage, financial harm or other damage.
External fraud means dishonest, deceptive or unlawful conduct committed by a person or organisation outside The Company, whether acting alone or in collusion with an insider, to obtain money, information, services or another benefit, or to cause loss or harm through misuse of The Company’s systems, products, services or business relationships.
Foreign bribery means the bribery of a foreign public official as outlined in Division 70 of the Criminal Code Act 1995 (Cth). Foreign bribery is corrupt conduct and a form of serious wrongdoing.
Fraud as defined by AS 8001:2021, is dishonest activity causing actual or potential gain or loss to any person or organisation, including theft of money or other property by persons internal or external to the organisation and conduct involving deception. It includes deliberate falsification, concealment, destruction or use of falsified documentation and improper use of information or position for financial benefit.
Identity fraud means the unauthorised use, manipulation or creation of personal or business identity information to deceive another person or obtain a benefit. It includes use of stolen, false or synthetic identities.
Internal fraud means fraud committed by, or involving, a Board member, manager, employee, contractor, consultant, agent or other person with an internal or trusted relationship with The Company.
Payment fraud means fraudulent conduct involving a payment transaction, payment credential, account, refund, settlement, chargeback, QR code or other payment instrument or process.
QR code substitution means replacing, altering or redirecting a legitimate QR code so that a payment or information is sent to an unauthorised destination.
Significant or systemic fraud means an incident of fraud, or a pattern or recurrence of incidents, that a reasonable person would consider has a significant impact on The Company’s customers, reputation, financial position, operations, regulatory obligations or control environment.
Social engineering means manipulating or deceiving a person into disclosing confidential information, providing access, changing account details or authorising a transaction or other action.
Synthetic identity means an identity created by combining real and fabricated information, or entirely fabricated information, for deceptive or fraudulent purposes.
Transaction laundering means using a legitimate retailer or merchant account to process payments for an undisclosed, unauthorised, prohibited or illegal business, product or service.
Victimisation or reprisal action means treating, or threatening to treat, a person detrimentally because they sought assistance, raised or proposed to raise a concern, made or proposed to make a report, or assisted with a matter under this policy.
10. Governance and review:
10.1 The Compliance Manager is responsible for maintaining this policy, coordinating fraud risk management activities and reporting material fraud matters to the CEO and Board.
10.2 Management is responsible for implementing fraud controls within its areas of responsibility and ensuring that personnel understand and comply with this policy.
10.3 The Board is responsible for oversight of The Company’s fraud and corruption control framework and for receiving reports about material incidents and control deficiencies.
10.4 This policy will be reviewed at least every three years and earlier where there is a material change to The Company’s business, products, systems, fraud risk profile, legal or regulatory obligations, or following a significant fraud incident.
POLICY APPROVER
David Thatcher, Director and CEO.
POLICY STEWARD
Compliance Manager
REVIEW
This policy is to be reviewed every three years, by 1 May 2029, or earlier in the circumstances described in clause 10.4.