Bulletin Board - Document Comments

Bulletin Board - Review and Comment

Step 1 of 4: Comment on Document

How to make a comment?

1. Use this Comment Icon to open a comment box for your chosen Section, Part, Heading or clause.

2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.

3. Do not open more than one comment box at the same time.

4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.

Important Information

During the comment process you are connected to a database.  The session that connects you to the database may time-out due to inactivity.  The following tips will help you to avoid losing your comments or corrupting your entries:

  1. Do not jump between web pages/applications while logging comments.
  2. Do not log comments for more than one document at a time. Complete and submit comments from one document before commenting on another.
  3. Do not leave your submission part way through the comment process. If you are part way through and need to take a break, submit your current set of comments. The system will email you a copy of your comments, so you will be able to identify where you were up to so you can add to them later.
  4. Do not exit the process until you have completed all three stages.

Fraud and Corruption Control Procedure

Section 1 - Summary

(1) This Procedure outlines Victoria University’s (VU’s) approach to preventing, detecting, and managing fraud and corruption risks. It operates in support of the Fraud and Corruption Policy, which governs the reporting and investigation of suspected misconduct.

Top of Page

Section 2 - Scope

(2) This Procedure applies to the prevention, detection and management of fraud and corruption across the University, and to all members of the University community, including: 

  1. Staff (including casual and sessional staff); 
  2. Students (including higher degree by research students); 
  3. Consultants, contractors and their employees; 
  4. Council members and members of its committees; 
  5. Honorary, visiting and adjunct appointees; 
  6. Volunteers; and 
  7. any other persons or entities who perform work for or on behalf of the University, including University partners. 

(3) This Procedure applies to university-controlled entities, onshore and offshore campuses and transnational education operations, including VU India, unless an approved local variation is required under the Third Party Arrangements framework. 

Top of Page

Section 3 - Policy/Regulation

(4) Fraud and Corruption Control Policy

Top of Page

Section 4 - Procedures

Part A - Summary of Roles and Responsibilities

Role Responsibilities
Fraud and Corruption Control Officer (Chief Risk Officer)
Oversees and implements this Procedure. 
Coordinates fraud and corruption scans. 
Oversees investigations into allegations of fraud and corruption, in accordance with the Disclosure and Whistleblower Procedure. 
Maintains the central register of reported incidents. 
Reports on fraud and corruption matters to the Audit and Risk Committee (ARC) and Council. 
 Council
Provides governance oversight of fraud and corruption risks. 
Receives reports on fraud and corruption incidents, outcomes and mitigation strategies through the Audit and Risk Committee. 
Audit and Risk Committee (ARC)  Oversees the University’s approach to fraud and corruption risk and promotes a culture of integrity and accountability.  
Reviews reports on fraud and corruption incidents, outcomes and remediation actions as appropriate.  
Reviews and endorses the outcomes of the fraud and corruption risk assessments. 
Escalates matters to Council, including investigation outcomes and strategic responses. 
Vice-Chancellor's Group (VCG) members  Promotes an ethical culture and supports the effective management of fraud and corruption risks. 
Ensures appropriate prevention and detection controls are implemented within their areas of responsibility. 
Ensures staff complete required fraud and corruption training and maintain relevant qualifications and checks. 
Escalates suspected fraud or corruption in accordance with the Disclosure and Whistleblower Procedure. 
Ensures appropriate actions are taken in response to investigation outcomes.
Office of the General Counsel (OGC) Provides legal advice to support the management of fraud and corruption matters 
Supports the Fraud and Corruption Control Officer in liaising with IBAC, law enforcement, insurers and other external bodies. 
Provides guidance on contractual and legal risk controls, including due diligence requirements. 
Ensures appropriate contractual protections are in place to mitigate fraud and corruption risks.  
Chief Financial Officer
Ensures appropriate financial and procurement controls are in place to prevent and detect fraud and corruption.  
Liaises with the Victorian Auditor-General's Office (VAGO) regarding audit procedures designed to detect material misstatements due to fraud or error. 
Procurement  Conducts due diligence on contractors and partners prior to entering significant engagements, including offshore and international arrangements. 
Identifies and manages fraud and corruption risks associated with procurement activities. 
Ensures compliance with the University's Conflict of Interest Policy in procurement decision-making. 
All members of the University community Reports suspected instances of Improper Conduct or misconduct, in accordance with the Disclosure and Whistleblower Procedure.  
Complies with requirements under this Procedure and other relevant University policies. 
Cooperates with fraud prevention, detection and investigation activities as required. 
Internal Audit  Considers fraud and corruption risks and incident data when developing the Internal Audit plan. 
Provides independent assurance on the effectiveness of governance, risk management and internal control processes. 

Part B - Fraud and Corruption Control Framework

(5) As a public body, Victoria University is subject to heightened scrutiny and must comply with all relevant legislative, regulatory, and governance requirements. The University is committed to maintaining the highest standards of integrity, transparency, and accountability in its operations, consistent with its obligations under regulatory and legislative frameworks.

(6) VU’s fraud and corruption control framework consists of four key elements:

  1. Planning and Resourcing;
  2. Prevention;
  3. Detection; and
  4. Response.

Planning and Resourcing

(7) A Fraud and Corruption Control Plan outlines the actions the University undertakes to prevent, detect and respond to the risk of fraud and corruption. 

(8) The Fraud and Corruption Control Officer has oversight over the University’s Fraud and Corruption Control framework and reports on its effectiveness to the ARC and to the University Council.  

(9) Internal Audit supports the University’s fraud and corruption control framework through risk-based audit activities and by considering fraud and corruption risks in the development of the Internal Audit plan.  

(10) Internal Audit liaises with the Fraud and Corruption Control Officer on suspected fraud or corruption detected as part of the internal audit program. 

(11) The University will periodically review the effectiveness of its fraud and corruption control framework, including controls, training, risk assessments and reporting mechanisms, to support continuous improvement. 

Prevention

(12) VU promotes an ethical culture and implements the following measures to prevent fraud and corruption:

  1. Ethical Culture and Behaviour
    1. The Staff Integrity Framework, together with the Appropriate Workplace Behaviour Policy and Student Conduct Policy, sets minimum standards for staff and student conduct, outlines professional expectations, and details consequences for unacceptable behaviour. 
    2. Leaders model ethical behaviour, which is reinforced through policies, training, and communication. 
    3. Staff and students are expected to act in the best interests of the University and uphold integrity and transparency in all activities. 
  2. Policy Framework 
    1. Fraud and corruption risks are minimised through a suite of policies including: 
      1. Appropriate Workplace Behaviour Policy 
      2. Conflict of Interest Policy 
      3. Financial Code of Conduct Policy 
      4. Gifts, Benefits and Hospitality Procedure 
      5. Academic Integrity Policy 
      6. Research Integrity Policy
      7. Purchasing Policy 
      8. Student Conduct Policy 
      9. Third Party Arrangements Policy
  3. Recruitment and Screening 
    1. Pre-employment screening is conducted for all prospective staff in line with the Recruitment and Selection Procedure, including: 
      1. Police and Working with Children Checks 
      2. Professional registration and qualifications 
      3. Fit and Proper Person assessments 
    2. Managers and staff are responsible for maintaining required registrations, qualifications and checks throughout employment. 
  4. Course and Program Integrity
    1. Robust course accreditation requirements help ensure academic integrity and reduce risks of misconduct in teaching and research. 
  5. Internal Controls 
    1. Controls include segregation of duties, delegated approvals, procurement protocols, budget monitoring, and information security. 
  6. Risk Assessment 
    1. Fraud scans are conducted at least biennially or when there is a substantial change in the structure, functions or activities of the University.  Risk assessments are conducted in accordance with ISO 31000 and the University’s Risk Management Framework
  7. Training and Awareness 
    1. Fraud and corruption awareness training is a mandatory staff training requirement delivered through VU Develop.  
    2. Managers are responsible for ensuring staff complete required training. 

(13) Where activities are undertaken through offshore campuses, controlled entities or third-party arrangements, fraud and corruption controls must be proportionate to the nature, scale and risk profile of those operations.

Detection

(14) The Fraud and Corruption Control Officer oversees fraud and corruption detection and works with business units and Internal Audit to implement appropriate detection controls based on identified risks. 

(15) The external auditor of Victoria University is the Victorian Auditor-General’s Office (VAGO). The Chief Financial Officer liaises with VAGO regarding audit procedures designed to detect material misstatements due to fraud or error. 

(16) The University periodically reviews and tests the effectiveness of fraud and corruption controls, including through internal audit activities, targeted reviews and data analytics, to identify control weaknesses and support continuous improvement. 

(17) Due diligence and screening processes apply to staff, contractors, and third parties engaged by the University, including partners and collaborators, as appropriate. Due diligence is undertaken prior to entering a contract of significant value or business relationships.  Contracts and agreements include provisions, where appropriate, requiring parties to attest to compliance and enable the University to take appropriate action where fraud or corruption is identified. Contracts and agreements may include provision where appropriate to allow the University to request information or conduct audits on suppliers or customers in relation to fraud and corruption risks.

Response

(18) The University ensures that reports of suspected fraud or corruption are assessed, investigated, escalated and reported to external authorities where required by law. All disclosures of suspected fraud or corruption must be reported in accordance with the Fraud and Corruption Control Policy and Disclosure and Whistleblower Procedure. Processes for reporting, assessment and investigation are detailed in the Disclosure and Whistleblower Procedure. 

(19) The University maintains appropriate insurance cover to mitigate financial losses arising from fraud, including cyber fraud.  

(20) All members of the University community, including students and staff, contractors and other relevant third parties, are expected to cooperate with authorised investigations conducted under the Disclosure and Whistleblower Procedure. 

(21) Fraud and corruption prevention and response activities are coordinated with cyber security, information security and data governance functions where relevant. 

(22) Where appropriate, the University will take timely action to contain and address suspected fraud or corruption, including implementing interim control measures to mitigate further risk or loss. 

(23) Matters involving significant financial loss, senior officers, systemic control failures, criminal conduct or significant reputational risk must be escalated immediately to the appropriate governance authorities. 

(24) Post-incident reviews of internal controls are coordinated by the Fraud and Corruption Control Officer and relevant business units to assess control effectiveness and identify required improvements, with findings reported to the Audit and Risk Committee (ARC). 

(25) The University may notify regulators, funding bodies, law enforcement agencies, insurers, auditors or other external stakeholders in Australia or overseas, where required by law, contractual obligations or regulatory requirements.  

Part C - Regulatory and Governance Reporting 

(26) This section relates to governance, statutory and regulatory reporting obligations following the identification or investigation of suspected fraud or corruption. It does not replace the requirement to report suspected misconduct in accordance with the Disclosure and Whistleblower Procedure. 

(27) Victoria University is required to comply with applicable legislative, regulatory and governance obligations, and is committed to maintaining high standards of integrity, transparency and accountability.  

(28) In accordance with Standing Direction 3.5 (2018) under the Financial Management Act 1994 (Vic), the Fraud and Corruption Control Officer maintains a central register of all reported fraud and corruption incidents, including details of remedial actions.  

(29) Following the assessment or investigation of a disclosure under the Disclosure and Whistleblower Procedure, where evidence of fraud or corruption is identified, the Fraud and Corruption Control Officer consults with the General Counsel and other relevant stakeholders to determine whether the matter should be referred to internal or external authorities, including law enforcement.   

  1. Statutory reporting obligations include: 
    1. In accordance with section 57 of the IBAC Act, the Principal Officer (Vice-Chancellor) must notify IBAC of any suspected corrupt conduct as soon as practicable. 
  2. Governance reporting includes: 
    1. Incidents involving senior officers or of significant value or complexity must be referred immediately to the Chancellor via the Chair of the Audit and Risk Committee (ARC). 
    2. All other incidents are reported to the ARC on a periodic basis. 
  3. External notifications: 
    1. Significant or systemic incidents may be notified to external stakeholders, including the Minister for Education, the Department of Education, the Auditor-General, funding bodies (such as the Australian Research Council), and other relevant government or regulatory bodies, where required by applicable legislation, Standing Directions under the Financial Management Act 1994 (Vic), contractual obligations or governance requirements.   

(30) The Fraud and Corruption Control Officer makes these reports through the Office of the Vice-Chancellor and, on advice from the General Counsel, refer serious or complex matters to law enforcement. 

(31) The University cooperates fully with any external investigations and provides assistance as required. 

(32) Records relating to fraud and corruption reports, assessments, investigations, outcomes and remediation actions must be securely maintained in accordance with applicable privacy, records management and legislative obligations. Access to records will be restricted to authorised persons on a need-to-know basis. 

(33) Periodic reporting to the Audit and Risk Committee and Council may include information regarding incident trends, substantiation rates, control weaknesses, remediation activities and emerging fraud and corruption risks. 

Top of Page

Section 5 - HESF/ASQA/ESOS Alignment

(34) HESF: Standard 6 Governance and Accountability: 7.1 Representation; 7.3 Information Management.

(35) Outcome Standards for NVR Registered Training Organisations 2025: Standard Standard 4.3 Risk Management; 2.7 Feedback, Complaints and Appeals. Compliance Standards for NVR Registered Training Organisations and FPP Requirements 2025: Standard 20 Compliance with Laws.

Top of Page

Section 6 - Definitions

(36) Corrupt Conduct or Corruption: For the purposes of the Fraud and Corruption  Control Policy and Procedures and mandatory notification to the IBAC, corrupt conduct is conduct, or an attempt or conspiracy to engage in conduct (whether it takes place inside or outside of Victoria) that: 

  1. Adversely affects the honest performance of the functions of a public officer or public body; or 
  2. Constitutes or involves the dishonest performance of the functions of a public officer or public body; or 
  3. Constitutes or involves knowingly or recklessly breaching public trust; or 
  4. Involves the misuse of information or material acquired in the course of the performance of the functions of a public officer or public body; or 
  5. Is intended to adversely affect the effective performance of the functions or powers of a public officer or public body and results in the person or their associate obtaining a specified benefit* . 

    The corrupt conduct would constitute an indictable offence against an Act, or the common law offences of attempt to pervert the course of justice, bribery of a public official, perverting the course of justice and misconduct in public office. 

    Bribery is a type of corruption; the act of paying a secret commission (either in money or in kind) intended to: 
    a. cause an employee to act contrary to the interests of the University; 
    b. is contrary to the University’s policy; or 
    c. is against the public interest. 

    A secret commission can be anything of value; any good or benefit reasonably perceived to be of worth. Examples may include gifts, travel, entertainment, hospitality, political contributions, charitable contributions, in-kind contributions, business, employment or educational opportunities, discounts, service, commissions or credit. 
    *(Independent Broad-based Anti-corruption Commission Act 2011 (Vic), Section 4) 

(37) Disclosure: A verbal or written report made to the University raising concerns about suspected fraud, corruption, improper conduct or other wrongdoing.

(38) Improper conduct: conduct that is dishonest, unlawful, unethical, corrupt, fraudulent, or otherwise inconsistent with the proper performance of public functions or responsibilities, including fraud, corruption and other serious wrongdoing. 

(39) Significant or systemic incidents: means an incident, or a pattern or recurrence of incidences, that a reasonable person would consider has a significant impact on the Agency or the State's reputation, financial position or financial management. The thresholds relevant to Victoria University are: 

  1. $1,000 for incidents involving purchasing and prepaid debit cards. 
  2. $5,000 in money. 
  3. $50,000 in other property. 

(40) Fraud: Any dishonest activity causing actual or potential financial loss to any person or entity, including theft of moneys or other property, by staff or persons external to the University and where deception is used at the time, immediately before or immediately following the activity. 
 
This also includes the deliberate falsification, concealment, destruction or use of falsified documentation used or intended for use for a normal business purpose or the improper use of information or position for personal financial benefit*. 
 
The theft of property by a person or persons internal to the University but where deception is not used is also considered ‘fraud’ for the purposes of the Fraud and Corruption Control Policy and Procedures. 
 
*(Australian Standard AS 8001-2008 Fraud and Corruption Control, page 15).