Advanced Money skill
Create a fraud response plan
Create an evidence-led fraud response plan spanning triage, authority, containment, affected people, and recovery.
When to use
- Use to design or repair an organization-wide response before or after a material suspected fraud event.
- Use a focused discrepancy investigation for one bounded payment case.
Preconditions
- Confirm executive sponsor, legal and investigation authority, emergency contacts, reporting jurisdictions, evidence systems, insurer and financial-institution channels, workforce process, and protected reporting routes.
Procedure
- Define a triage boundary by allegation type, harm, amount, velocity, privilege, safety, regulatory exposure, and evidence risk.
- Map intake channels, protected disclosure, conflict checks, case assignment, independence, and alternate authority when leaders are implicated.
- Establish evidence preservation for documents, messages, devices, identities, logs, financial records, physical material, custody, retention, and legal hold.
- Build decision rights for case opening, access restriction, payment hold, customer protection, external notification, employee action, recovery, and closure.
- Coordinate containment across finance, security, operations, legal, people, communications, insurers, banks, platforms, and law enforcement only through authorized owners.
- Protect affected parties through urgent service, account, payment, identity, safety, accessibility, privacy, and anti-retaliation measures.
- Define investigation planning, hypotheses, corroboration, interview governance, expert use, status reporting, and disclosure boundaries.
- Prepare recovery options for funds, records, access, customers, suppliers, workforce, operations, controls, and public commitments.
- Rehearse an executive conflict, compromised mailbox, payment diversion, continuing customer harm, evidence loss, and premature public leak.
- Review exercises and cases for control effectiveness, recurrence, systemic causes, overdue actions, and plan revision.
Failure plan
- Stop any action that could destroy evidence, alert a suspected actor, endanger a person, prejudice due process, or breach required confidentiality.
- Do not promise anonymity, recovery, prosecution, employment action, or reporting outcomes beyond authorized control.
- Escalate immediate safety risk, leadership conflicts, material loss, cross-border issues, and mandatory reporting questions to qualified independent owners.
--- name: create-a-fraud-response-plan category: money description: Create an evidence-led fraud response plan spanning triage, authority, containment, affected people, and recovery. Use when an organization needs a safe operating model for suspected internal, supplier, customer, payment, or digital fraud. --- # create-a-fraud-response-plan ## When to use - Use to design or repair an organization-wide response before or after a material suspected fraud event. - Use a focused discrepancy investigation for one bounded payment case. ## Preconditions - Confirm executive sponsor, legal and investigation authority, emergency contacts, reporting jurisdictions, evidence systems, insurer and financial-institution channels, workforce process, and protected reporting routes. ## Procedure 1. Define a triage boundary by allegation type, harm, amount, velocity, privilege, safety, regulatory exposure, and evidence risk. 2. Map intake channels, protected disclosure, conflict checks, case assignment, independence, and alternate authority when leaders are implicated. 3. Establish evidence preservation for documents, messages, devices, identities, logs, financial records, physical material, custody, retention, and legal hold. 4. Build decision rights for case opening, access restriction, payment hold, customer protection, external notification, employee action, recovery, and closure. 5. Coordinate containment across finance, security, operations, legal, people, communications, insurers, banks, platforms, and law enforcement only through authorized owners. 6. Protect affected parties through urgent service, account, payment, identity, safety, accessibility, privacy, and anti-retaliation measures. 7. Define investigation planning, hypotheses, corroboration, interview governance, expert use, status reporting, and disclosure boundaries. 8. Prepare recovery options for funds, records, access, customers, suppliers, workforce, operations, controls, and public commitments. 9. Rehearse an executive conflict, compromised mailbox, payment diversion, continuing customer harm, evidence loss, and premature public leak. 10. Review exercises and cases for control effectiveness, recurrence, systemic causes, overdue actions, and plan revision. ## Failure plan - Stop any action that could destroy evidence, alert a suspected actor, endanger a person, prejudice due process, or breach required confidentiality. - Do not promise anonymity, recovery, prosecution, employment action, or reporting outcomes beyond authorized control. - Escalate immediate safety risk, leadership conflicts, material loss, cross-border issues, and mandatory reporting questions to qualified independent owners. ## Done - A response authority map names primary and alternate decision-makers, conflicts, thresholds, and escalation routes - An evidence and decision log model preserves intake, custody, facts, hypotheses, actions, approvals, and disclosure - Scenario records prove the triage boundary, coordinated containment, and affected-party protection under failure - Recovery verification confirms fund and record disposition, service restoration, control repair, communication, and recurrence review