09:30
Agenda item 2 is consideration of the report “The National Fraud Initiative in Scotland 2026”. I welcome our witnesses, who are all from Audit Scotland. They are: John Cornett, executive director of audit services; Martin McLauchlan, a senior manager; and Tim Bridle, an audit manager. I invite John Cornett to give an opening statement.
Thank you for the opportunity to present the report. I will keep my opening statement quite brief, as I am keen to get into conversation with you. Tim and Martin undertook the detailed work on the national fraud initiative, so they will pick up on some of the more detailed conversations and questions that members might have.
The report in front of us was published in August 2026, and it represents the conclusion of the work on the 2024-25 national fraud initiative’s data matching exercise. The national fraud initiative is a United Kingdom-wide exercise that is undertaken every two years. It is designed to prevent and identify fraud and error.
Data matches are not conclusive evidence of fraud, but they are indicative of potential fraud or error, and they highlight areas that are worthy of further investigation. We undertake our work in Scotland in partnership with the Public Sector Fraud Authority, and the report summarises the outcomes from the work that we have undertaken.
There are 127 organisations in Scotland mandated to participate in the exercise, and around 1,000 organisations across the UK. The work that we do on the national fraud initiative is particularly important, given the ongoing pressures in the public sector and the need to secure probity and regularity in transactions that take place in the public sector.
Beyond financial recovery from fraud and errors that are identified, the exercise also acts as a deterrent. One of the requirements of the exercise is that all employees who work in an organisation must know that the exercise is taking place, and that visibility acts as a strong deterrent across the sector.
Cumulative outcomes since the work began in Scotland, nearly 20 years ago, in 2006-07, total approximately £201 million. The 2024-25 exercise generated total reporting outcomes of just under £22 million—about £21.7 million. Those outcomes are split into three broad areas. Roughly £6 million comes from overpayments or additional income that is due to organisations, just under £9 million is in estimated forward savings and additional income that will be received in the future, and about £6.8 million is made up of notional outcomes that are estimated through the work that we have undertaken.
The three main areas where savings have accrued are recovery of overpayment of pensions, where the amount is about £4.8 million; council tax single-person discount—which means instances in which people have inappropriately claimed the single-person discount—where the savings are about £4.1 million; and the council tax reduction scheme, where there are savings of about £1.7 million. Those are the three main areas where savings accrued from the 2024-25 exercise. The outcomes in the 2024-25 report are slightly less than those in the previous exercise, but we have concluded in the report that the NFI continues to play a vital role in protecting public funds, deterring fraud and preventing errors from arising.
Excluding housing benefit outcomes, overall outcomes have increased. There is a link between the workload that goes through the housing benefit system. Because that workload is decreasing there is consequently a decrease in issues arising through housing benefits. We have also reported that there is an improvement in the delivery of NFI, with fewer bodies having significant issues in following up the data matches and investigating them, which is a positive outcome. However, we recognise that there is still scope to improve timeliness with better and more focused follow-up of the data matches.
We make four recommendations in the report. One is around using the NFI self-assessment checklist at the level of the individual audited body or organisation, to ensure that the planned approach is clearly articulated and gets best value from the work that is undertaken by an individual organisation. The second is to review payroll-to-payroll matches sooner—that is, as soon as those matches become available—rather than waiting for the exercise to conclude.
The third recommendation is to put in place arrangements for regular monitoring and follow-up activity and, where necessary, to seek to understand the reasons where there are low or nil returns. It is about not simply accepting a low return as an outcome but trying to understand the reasons behind that and what activity a body is undertaking to support that. The fourth is that, where auditors have identified delivery issues around the NFI exercise in their individual annual audit reports, it is incumbent on bodies to follow up the recommendations in those reports.
We will continue to work with public bodies and the Public Sector Fraud Authority to support the effective and efficient delivery of NFI through our ongoing activities.
I will pause at that point. I am happy to explore any of the issues that I have talked about. If there are issues that you thought I was going to talk about but that I did not, I am also happy to pick those up.
Thank you for your report and your opening statement. We are keen to explore more of the details around the fraud and error that have been identified.
In opening, I will ask about some of the potential gaps. Are you able to estimate in any way the levels of fraud in the public sector in Scotland that have not been identified by the national fraud initiative?
The short answer to that is no.
We struggle to access data that is not part of the national fraud initiative. We do not extrapolate from the data that we have in order to draw a conclusion or to cover the data that we do not have. However, you could probably take that as a proxy for the level of fraud that exists. It does not necessarily identify all fraud, but it covers most of the areas that are susceptible to fraud and where there is a high risk of fraud. My view is therefore that we cover most, but not all, areas of fraud.
Good morning, all. I do not have much to add.
Certain categories of fraud, such as cyberfraud, are not something that we look at specifically within the NFI. However, what we have done over time, and what we continue to do, is gain coverage through new data matches, new ways of investigating fraud and error, and the work that Tim Bridle continues to do on how effectively issues that are identified are followed up.
As John Cornett said, we cannot extrapolate from the NFI data, but it provides that wider aspect of assurance as well as deterrence.
On page 16 of your report, in section 27, you state that you will
“consider expansion of the exercise during discussion of fees with the PSFA”,
which is the Public Sector Fraud Authority. What would need to come of those discussions to expand the exercise?
I will respond to that and will then perhaps bring in Tim Bridle, who is quite involved in the detailed work around that.
The fundamental thing that we need in order to expand the exercise is agreement on the areas that will be subject to data matching. Bodies have to sign up to data matching in those areas, and the PSFA then has to co-ordinate that work nationally. We could do something locally in Scotland, and we are exploring that. Tim will pick up on that point.
Fundamentally, it is about bodies being able to access the data and then provide that data—that is the key issue. At the moment, we are working on the basis that the exercise is mandated for all of those bodies in relation to which the Accounts Commission or the Auditor General is responsible for appointing the auditor. Any participation beyond that is on a purely voluntary basis. Some of the work that Tim Bridle is doing is about expanding that voluntary participation in the exercise, and we are piloting some of that, particularly for universities. A number of factors have to be in place if we are to be able to expand the exercise.
Tim, do you want to share some insights into the work that you are doing?
We have a couple of pilot exercises at the moment, which are looking at areas where we data match. For example, we are doing some work with Social Security Scotland to look at residency checks on some of its payment streams, and there will be an expansion if that proves to be fruitful. We also have a pilot with the City of Edinburgh Council, which is looking at offering short-term council house lets via online platforms, which would also represent an expansion. The third area that we are looking at is second homes. We have a working group that is looking at how we can help to identify what we call “silent” second homes—second homes that people have declared to be main residences in order to avoid paying premium council tax. Those are the areas we are working on.
We have invited a few more bodies to participate in the next exercise, and one of the universities in Edinburgh has volunteered to participate. That will be a useful pilot for that sector, and it will be interesting to see whether they get good value from participating.
Before turning to other members, I will ask a specific question about the adult concessionary travel scheme. You have reported that an estimated full-fare value of £200,000 of fraud has been identified where bus passes were used and
“where the passholder’s death had not been previously reported”,
leading to an underlying cost of £110,000 to Transport Scotland. Have you any further details about the number of times that has occurred or the number of passes that have been misused?
Tim has the detail on that, so I will hand over to him.
I apologise—I could probably have included that in the report. The last matching run that we did showed that just over 600 passes were used fraudulently after the date of the passholder’s death, with that figure representing around 1 per cent of all badges that were cancelled. I do not have a breakdown of the figures, but there will be a distribution of usage, with a number of those passes having been used extensively, persistently and to a high value and others having been used just once or twice.
You are saying that 600 passes that were used had belonged to passholders who died. Who was using those passes?
That is a good question. Transport Scotland follows up on any potentially fraudulent use. There is a careful process of cancelling passes, because it wants the opportunity to catch people in the act. The difficulty is that we do not know that fraud is happening unless people are caught. As the passes are matched, cleared and cancelled, there is a timeline that enables Transport Scotland to follow up, and I would have to defer to it regarding its findings. I am not sure whether it has actually caught many people in the act, as it were.
Everyone over the age of 60 is entitled to concessionary travel, so one would assume that it is people who are under 60 who are fraudulently using those passes.
Exactly. We do not look at minors; we look just at the adult concessionary travel scheme, which is for disabled people and the over-60s.
That leads on to my other question. We are looking at adult concessionary travel and at fraudulent use of passes belonging to over-60s who have died. There is nothing in today’s report about possible fraud by young people. Why is that?
I think it is a policy thing. The national fraud initiative does not look at minors. I am not sure that I can tell you why not, but we do not do that.
When you say “minors”, do you mean under-16s?
We mean young adults. I am not sure whether that means those under 18 or under 16, but we look only at adults.
Young people under the age of 22 receive a free bus pass, so there is nothing to prohibit your looking at that age group.
09:45
Yes. You have got me there—that is a good question. I would have to clarify whether we include over-18s and under-22s. I have a feeling that we probably do, but I am on unsure ground—you have caught me cold on that one, I am afraid—so I would not like to commit definitively.
There is a timing issue, too, because these are the outcomes of the 2024-25 exercise, and, from memory, the under-22 policy came in—
It came in before that.
It was prior to that, but there might have been a lag in setting up the systems to enable that.
You have identified that there is the potential for fraud in relation to older persons’ bus travel, so there would certainly be potential for fraud in relation to younger persons’ bus travel, through peer-to-peer or inter-household sharing of bus passes. Could more be done to identify such fraud? There is no mention of that as a possibility in the report, but you think that that can be investigated in future years.
I would not give that commitment. We can discuss that with the PSFA, and Tim Bridle can take that forward with the forum that he interacts with. It is obviously a Scotland-specific policy, so it might be that we can conduct a type of data matching exercise in Scotland. We can certainly give an undertaking that we will take that issue away, explore it and, if possible, look at how we can roll it into future exercises.
We will now have questions from members, and Miles Briggs is first.
Good morning, and thank you for joining us. Tim, you mentioned universities, and I think that you said that one university has now agreed to be part of a pilot exercise. I am interested in the part of the report that states that you had invited universities to take part on a voluntary basis in the past, so it is good to hear that this might be the start of universities coming forward. Given the financial crisis that universities are facing, to what extent do you believe that participating in NFI and, potentially, identifying fraud and error in their systems would be beneficial? From your experience, what might you find?
There are a number of aspects to that question. There is the element around the assurance process. NFI provides bodies with a significant degree of assurance around the operation of their controls and processes, as well as data matching in relation to identifying potential fraud. However, the fact that data is matched does not necessarily mean that the fraud exists in that organisation—it might exist somewhere else—so a balance needs to be struck.
The work that we are doing with the university is a pilot-type exercise to understand the scale of matches that we might get and what assurance the bodies might take from the exercise itself. We hope to be able to use that almost as a pitch to bring other bodies into the exercise. It could be that having a single university take part in its own right does not give rise to many data matches, because the data matches might be with other universities and, if those universities are not participating in the exercise, there is a potential gap. We will need to explore that and understand it.
The other challenge in relation to universities—as well as other bodies—is the data sharing requirements while necessarily complying with the general data protection regulation requirements. We think we have a solution to that, which is what we are piloting through the university that Tim referred to. If that works, it will open up the opportunity to expand the work elsewhere. Fundamentally, it comes down to whether the body will get benefit from the exercise, and I think that that comes from the assurance in relation to processes and systems. There is a challenge in relation to the data matches, and we need to explore what that might look like and how we might be able to take that forward, depending on the data matches that exist.
Tim, do you want to add anything?
To start with, the main data match areas are payroll and creditor payments. We have had a good level of identification of duplicate creditor payments. That is a direct saving for the bodies involved, which can seek credit notes or recovery as appropriate. That is the main area of monetary benefit that they can get, in addition to the assurance and deterrence that John has mentioned.
These are all independent institutions. Is it easy enough for all universities to provide the data sets? When I was on the Education, Children and Young People Committee, we did a lot of work on the University of Dundee situation, and it seems that universities often have different processes for accounting and finances. They are complex organisations when it comes to budgets, legacies and so on. If the participation of universities is to go ahead in the future, perhaps there should be a framework, which you could work on with Universities Scotland, so that it could go live more quickly than if it were just one pilot.
Again, Tim is closer to the detail on that, so I will ask him to come in.
Fundamentally, for most organisations, the data has to be put into a certain format. A piece of work at the organisation level is required to be able to do that, which is simply because different organisations use different systems and ledgers that are configured slightly differently and work in slightly different ways. We are used to going through the process to get the data into the required format when delivering the exercise. Tim might have more insights on the situation with universities.
Yes. It is not too onerous. For new bodies to participate, there are some governance hurdles to clear under UK GDPR, including data protection impact assessments and privacy notices. The data then has to be extracted, which is fairly straightforward for information technology folk, I believe—I would probably find it quite challenging. Once the script has been written, the same script is used every time that the body participates. If we can demonstrate that it is not a lot of work for universities and that there is value in it, I am very hopeful that we can get more on board. Ideally, it would be good to get them all on board, as Miles Briggs said.
There are wider benefits from the data matching haul of data, because, in addition to providing matches back to the university, its payroll data, for example, would be matched with council payroll data and other council data sets for things such as single-person discount and council tax reduction schemes. Wider matches might indicate that someone who is claiming a council tax reduction, for example, has undeclared income. It is a win on both sides.
Reading the report, it struck me that there are organisations—specifically, the national health service—that are not involved when there would be a lot of merit in and benefit from their being involved. There will obviously be a lot of public service reform during this parliamentary session, so I would like to get your view on other organisations using the initiative, especially if we are going to move to having much larger bodies. Is it an opportunity to ensure that there are data sets and an investigative function in place early on, in order to prevent potential fraud?
I might bring in Martin McLauchlan on that in a moment. The NHS Counter Fraud Authority delivers work across the UK to prevent and detect fraud in the NHS. Therefore, a deliberate decision was made to exclude the NHS from the initiative, simply to avoid duplication. We could be challenged if we simply repeated the work that another agency was doing, so we have tried to avoid duplication by excluding the NHS. All the other public sector bodies that are included are those for which the auditor is appointed by the Auditor General for Scotland and the Accounts Commission, and we go through a decision-making process on their inclusion. In essence, there is a cost benefit assessment of the value of including all organisations. Consequently, 127 organisations are included in Scotland, as we have reported.
That does not mean that we are not open to including other bodies. As we have talked about, we are very open to the idea of other bodies participating voluntarily, but there has to be a genuine reason why the data matches could work, because if an organisation wants to join, but the data matches would not work, it is almost wasted effort. We are not closed to the idea of bringing other organisations in, but, as I say, we are conscious of the duplication, and of the benefit that might accrue from their participating in the exercise.
Martin, do you want to add anything?
Yes, I will just talk through that process. A large factor in why certain bodies will not be included is size and scale. For a very small body, the costs of running the exercise as a whole will outweigh the benefits.
The other side of that is that, as we mention in paragraph 9—this is where John Cornett may get me into trouble—we audit 226 organisations—
Is it not 250?
It is 250; 127 take part in the NFI, but some of those bodies are included by proxy. Councils will be included, depending on their relationship with certain arm’s-length external organisations and the system sharing that they have in place. So, 127 perhaps understates the number, but there is a specific rationale for why we do not include some bodies.
I go back to your opening statement, and this is also mentioned in the report. You highlighted £6 million of overpayments and additional income. Could you dig down a bit deeper into whether those overpayments were made as a result of purposeful fraud or administrative errors?
Tim Bridle will have a lot more of the detail on that than I do.
Fundamentally, we generally do not make that distinction in the report, because the report is written at a point in time when fraud investigations or investigations of data matches may not have concluded. They may have concluded that there is an error or an issue but may not have concluded whether that is deliberate fraud or an administrative oversight. Although the issue can be identified and the saving can be quantified, more work might still be needed behind that.
We generally focus on the total that we are looking at rather than the underlying reasons. We are very clear that investigating and concluding on that is a management responsibility of the individual organisation. Organisations will have their own reporting mechanisms to highlight this but, fundamentally, we approach it at a much higher level to quantify the issue and the work behind that.
Tim, do you have any more detail?
It is a tricky one. It is a balance of probabilities as to whether something would be judged as fraud or error. A lot of the additional income could relate to the single person discount, for example—if someone has moved in and has forgotten to notify. That could be deliberate or it could be an error.
Likewise, it may well be that someone who is in receipt of a council tax reduction has returned to work but forgotten to declare their income. There will be a mix. It is fair to say that people have busy lives and make genuine errors. However, you get to the point at which, on the balance of probabilities, some of that is fraud.
Is there any mechanism for looking retrospectively at previous years, once those kind of investigations have gone by, to give us an idea of how many people are purposely defrauding the state?
Realistically, probably not. We get some prosecutions of payroll, which is a bit clearer. For example, someone may have been doing two full-time jobs, which could lead to dismissal and a prosecution. However, for a lot of the recovery around SPD and the council tax reduction scheme, I am not aware there is ever anything categoric in terms of a prosecution. I suspect that that is because it is less frequent and the information is not readily collectible.
10:00
I can give a tangible example of that, which relates to John Cornett’s point about the timing issue. When there has been a duplicate payment because an organisation has been invoiced twice, the NFI will flag up the fact that that invoice has been paid twice. It will not identify whether that is an error, because there has been a delay in payment by the public body and a second invoice has been issued, or whether a second invoice has been issued with the express purpose of being paid twice. Our expectation would be that the NFI match would flag that, the public body would investigate it and then, as Tim Bridle said earlier, it could seek a credit note or recovery.
That does not take place in isolation. We would expect those outcomes to be reported appropriately within the individual body’s governance frameworks, but there are wider professional networks whereby if, for example, a corporation has defrauded a council, that knowledge will be shared.
The other thing to bear in mind is that, even if there is fraud, that does not necessarily always result in a prosecution. It can often be dealt with through disciplinary processes within the organisation, and we do not get particularly close to such processes as part of the NFI exercise.
There can be a range of outcomes, some of which are more visible than others, so it can be difficult to do a retrospective review to understand what the outcome has been.
Alan Brown has a supplementary, as well as some other areas that he wants to ask about.
I will start with the supplementary. I recognise what you have said, but, following on from Dawn Black’s questions about looking at things retrospectively, it strikes me that, given that the whole process is called the national fraud initiative, we should be able to gain a wider understanding of how much fraud there has been, relative to error or underpayment. That seems fundamental, given the title of the exercise. Therefore, I would have thought that somebody somewhere should look at what the scale of fraud is, with a view to understanding that and improving systems.
Meeting the definition of fraud is quite a high legal bar, so organisations often do not pursue the issue to the nth degree, because they might well not meet that high legal bar. However, an organisation can still take action to address the issue. For example, as Martin McLauchlan said, it could recover the overpayment of the duplicate payment.
If an organisation wants to carry out an investigation into whether the second invoice was issued fraudulently, it would have to consider whether that invoice was issued simply because of an administrative process. An organisation might have a process whereby, if an invoice has not been paid 30 days after it was issued, a reminder invoice is issued. If both invoices get paid, that is simply a process issue. It is for the organisation to decide whether it wants to get involved in the detail of investigating the situation or whether it is satisfied that recovery of the overpayment is sufficient.
Most organisations do not go beyond the point of recovering the overpayment, because the activity that would be required to proceed with a fraud investigation could be quite expensive. There is a process that organisations go through. Because the work usually stops at the point of recovery, that makes it incredibly difficult to conclude whether such overpayments were the result of fraud or of error. That is simply down to organisations deciding that the economic value of pursuing the matter further might be disproportionate to the value of the transaction.
Martin, do you want to expand on any of that? I am sorry; I should have given you a heads-up.
That is fine—thank you, John.
As far as the semantics of the title of the exercise are concerned, I think that the purpose of the national fraud initiative is not only to highlight areas of fraud and error; it has the wider purpose of highlighting weaknesses in controls and systems. Although I take your point about the title of the exercise, the NFI is about the wider aspects that we have spoken about; it is not simply a case of saying, “It’s resulted in X prosecutions.”
I am probably being a pedant, but I note that the initiative is actually called the national fraud, overpayment and error initiative, not just the fraud initiative. It is probably a Government badging thing.
Moving on, I know that you will not be able to give exact detail on this, but according to the forward look, one of the biggest things predicted relates to the recovery of pension overpayments. I presume that you will not know how much of that is fraud or just a matter of people not knowing how to report the death of a spouse. There might be an emotional issue involved, or pensions might be getting paid into an account that the person in question does not have access to or that they are unaware of. Is that correct?
Again, I will ask Tim Bridle to come in with some of the detail, but you are absolutely correct: the data matches match mortality against pensions. There might be a whole number of reasons for an individual not notifying whichever pensions agency it is of somebody’s bereavement, not least the fact that that might not be top of their list when a person passes away.
There is work on this that can be done nationally. This has already been referred to, but you could have a tell-us-once system in which the agency that you tell shares the information more broadly across other public agencies. Where there has been such an approach, it has been very successful in preventing the likes of pension overpayments, regardless of whether they have happened by error or fraud. That sort of process provides a strong control; however, it is dependent on an individual notifying whichever agency that somebody has passed away, and it is also difficult to determine whether an overpayment is fraudulent or has happened by error.
You could argue that, if somebody allows it to continue for a long period of time—and there have been examples elsewhere in the UK of pensions continuing to be paid for 10, 15 or 20 years—such activity, at some point, becomes fraudulent, because you must know that you cannot claim a pension for that long after somebody has died. However, it is a fine line between error, oversight and fraud.
I just want to flip things round slightly for my final question. Obviously, the initiative requires a lot of data sharing in order to understand people’s financial circumstances. I note that one of the benefits that is underclaimed is pension credit; the UK Government is always encouraging people to check whether they are eligible for and due pension credit, as it is also a passport to other benefits. Could the UK Government, if it so desired, use these data sharing platforms for the wider scheme, in order to understand who is eligible for, say, pension credit but is not claiming it?
I will bring Tim Bridle in on this, but yes, that is possible. Some of the data matching exercises that we carry out do highlight where people have underclaimed pensions that they are entitled to, so there is almost a positive benefit to individuals from some of this work. However, what you suggest would require some work on data protection requirements to bring the data set for UK pension credits into the system, and configuring the system to do the matches would require quite a lot of work, too, but theoretically it is a possible data match. I am content to take that away and see what can be done about it, but that would have to happen on a UK-wide basis, because of the way in which the pension credit system works.
Tim, do you want to add anything?
There are a couple of things to say. First, with regard to pensions, we do mortality screening of deferred pensions—that is, those instances where someone has moved employer, and their pension has sat there and not crystallised. Often, when we identify a bereavement in such cases, the person’s estate or spouse will receive the deferred pension, so that is a benefit. Indeed, it also helps the pension fund administer pensions if it can, for example, pay deferred pensions that are due. Therefore, this is not all about stopping payments. Sometimes payments are enabled, which is a good thing.
We are a little bit limited in what we can match. Our statutory powers concern fraud prevention, essentially. We do not data match for things such as debt recovery. However, I am aware that, for example, councils explore ways of identifying where there are benefits that have not been claimed, because that has a knock-on effect in terms of council tax arrears and so on. It is important that people receive what they are entitled to, as that helps councils collect amounts that are due. That is very much within the remit of those bodies, whereas we are limited to a certain extent in that regard. We would have to explore what we could do under our fraud powers, as it were.
But if there was a will, there could be a way. The scripts could be written and the powers could be used, if there was a will to do that.
Theoretically, there is a potential fraud element to bear in mind, as there could be pension credits that are being claimed when they are not entitled to be, either because of the person’s income or because the person is deceased. We could investigate and see what the art of the possible is in taking that forward.
The general issue of social security is related to pensions. Earlier, you mentioned the pilot that is taking place with Social Security Scotland on residency checks in relation to welfare payment recipients. Page 17 of the report says:
“If the pilot identifies significant levels of fraud, we will incorporate the match into future NFI exercises from 2028/29.”
What, in your view, would constitute significant levels of fraud? The reason I ask that is that, previously, you have qualified Social Security Scotland’s accounts due to millions of pounds of estimated fraud and error, but previous reports have also indicated fewer than 20 cases of clients who were not entitled to benefits.
It is a subjective judgment. However, there are two elements to the transactions and to the benefits that Social Security Scotland pays. There are those that sit within Social Security Scotland that the organisation is responsible for and pays, and there are those that are currently being paid by the Department for Work and Pensions on behalf of Social Security Scotland. I am very aware there is a transition process to bring the DWP payments into Social Security Scotland, but, at the moment, we do data matches only on those transactions that sit within the remit of Social Security Scotland. Fundamentally, what we would need to do is to understand what the additional transactions are and what the scale and potential scale of fraud or error in those transactions is.
There are two ways of looking at whether there is a significant level of fraud. One is the volume of data matches—whereby a high volume of data matches, albeit of a low value, would be a significant indicator—and the other is the value of the data matches themselves.
What we have not done is set out at the very beginning of the process the benchmark—that is, X number of cases and Y value of cases—that would meet the definition of “significant”. What we want to do is to see what the outcome is. However, regardless of the outcome, there is not necessarily a blanket yes or no in terms of whether we proceed with the process, because it might well be that the data matches indicate that more work needs to be done and more thought needs to be given in relation to the data matches to enable us to understand what the impact is.
I am conscious that that is not a direct answer to your question, but, fundamentally, what we want to do is to wait and see what the outcome looks like first, and then come to a view on what the next steps should be.
Earlier, we discussed the problems around looking at Scotland-specific policies, such as the Scottish child payment and the adult disability payment, which are not currently covered in the report. Will that pilot look at all benefits that people receive through Social Security Scotland that are subject to the residency checks?
10:15
I will bring Tim Bridle in on that, convener.
The main payment streams will be included. It is in essence just a residency check. Whether it becomes business as usual is the value in the exercise, and that will be the case on both sides.
If Social Security Scotland finds that it is not a fruitful avenue, we would not go ahead. Likewise, we need a certain amount of actual fraud. The fraud risk is there. Obviously, some of those payment streams are particular to Scotland, or are perhaps slightly higher in Scotland, so there is an incentive there for cross-border flows, as it were.
I would not like to say that I am 100 per cent certain that it is all payment streams. We have yet to do the matching run. I understand that it is the main ones, and it will include adult disability payments, for example, which is obviously a key stream in terms of value.
I will pick up on a point that my fellow pedant here made. The name does not seem right. It is more of a national financial audit than a national fraud initiative, is it not? You are looking for aberrations that may or may not be fraud but could just be sloppy bookkeeping. Is that correct?
I am very conscious that I do not want to get into a debate around semantics. Having said that, I know that the origins of the exercise were in England and Wales close to 30 years ago, when the scope and the scale of the data matches were much narrower than they currently are. That work was very much driven towards identifying fraud—that was its raison d'être.
The geographical coverage of the work on data matches has expanded considerably over that time. The name has not changed, so I think that your assessment is probably correct, but I do not know whether we want to get into a debate about what the name should be.
That is fair enough.
Once you identify a financial aberration in a book somewhere, what happens? What are the next steps? What is the mechanism to rectify that? Do you go back to the organisation to ask it to identify the issue first, or do you contact the police?
Again, colleagues will correct me if I am wrong but, fundamentally, the exercise provides a series of data matches to individual organisations. Those data matches are prioritised into high, medium and low risks, and a series of algorithms in the system do the categorisation. The information is provided to the individual body, and it is for that body to investigate and follow up those data matches. It then becomes a management decision as to whether any of those data matches need to be referred to the police. It is not an auditor’s responsibility in that respect; it is a management decision.
That goes back to our earlier answers. Often, the matters are dealt with through an internal disciplinary process when something genuine needs to be looked at. Occasionally, the police are brought in, and sometimes that is when we have recovered the overpayment, whatever that might be, and we draw the line there.
The responsibility for the follow-up sits with the individual organisation. What individual auditors do on our behalf is assess the adequacy of the follow-up work that those bodies undertake in terms of timeliness, pace and thoroughness, and give an overall view of the adequacy of that follow-up, but it is a management responsibility to follow up the data matches.
I draw your attention to exhibit 1, which sets out that process. The NFI provides the matched data, and then it is incumbent on the body, as John Cornett said, to take those steps. We have the classic auditor’s role of assessing the internal systems of controls, rather than detecting fraud on behalf of the body, or indeed following up the matches on behalf of the body. It is very much a data provision exercise.
You have identified £22 million of potential savings, recoveries and notional payments going forward. However, the Scottish Government’s spending this year is to be £120 billion. Although £22 million is a big number in itself, it is not a large proportion of Government spending. What is the total spend universe that you have audited to come up with that figure of £22 million?
There are two points in that. First, yes, nearly £22 million as a result of fraud, error or administrative oversight has been identified, but the exercise gives assurance on the rest of the number that you talked about, on which there are no issues. Bodies take a lot of assurance from how small the number is in proportion to the totality.
I think that Tim Bridle has more detail on the total value of the transactions that are part of the exercise. However, as I said, the key thing is assurance over the bit that is not shown as a data match, as well as the data matches themselves.
I am not sure that I have an awful lot more detail about the spend universe, to be honest—not at my fingertips. We could probably come back to you on it. The coverage of the whole council tax base, for example, involves big figures, as do the payrolls for all the audited bodies. I do not know what those figures are. I apologise that I am ill-prepared in that regard.
We can come back in writing if you require that. As John Cornett rightly pointed out, we also look at the nature of the transactions. My knowledge will be slightly outdated, but councils spend probably £18 billion a year, and 60 or 65 per cent of that is on staff costs and salary costs. That alone gives you an idea of the NFI’s coverage.
It is not as simple as looking at the totality of spend. It is about the nature of the spending that is covered in the NFI. We can give you figures for the expenditure of the 127 bodies—gross expenditure, net expenditure and so on—but, really, the exercise is about assurance and the nature of the matches. The council tax base is covered; payroll is covered. That is a significant amount of spending not only for councils but across the public sector.
We will provide the information if it is wanted, but I am not quite sure how helpful it is.
It would give me a better understanding of the scope of what you have found in terms of the totality of what you have inspected. It would be very useful.
How much does the NFI programme cost to run per year?
For this exercise, £220,000 in fees was paid to the Public Sector Fraud Authority. That is the direct fee for the public bodies in Scotland taking part.
The actual cost is higher than that. We could quantify our direct staff costs, and other costs will relate to individual bodies, depending on their size. For a small body, it might take one or two days to follow up a match, while a large council could involve weeks of work. However, the majority of direct cost is covered as part of the day-to-day duties of existing staff. The additional costs are a small proportion of our internal time. The indirect costs are from the input by other public sector bodies.
The direct cost for the exercise is therefore £220,000 plus whatever our overhead is. That has generated, as you said, £6 million in direct savings and £20 million in total. If the underlying point of your question is whether we see value in continuing the exercise, we can give an unequivocal yes.
Is the main value of the exercise in the assurance of the existing accounts and the deterrence of future fraud?
Yes—I think so. That is fundamentally where the value is. If the exercise did not take place, or if we put some sort of economic value on where we pitched the level of data matches, that would, in effect, transmit a message that a certain level of fraud or error was acceptable. What is not something that we would sign up to as auditors, when it comes to addressing fraudulent issues.
The value lies very much in the assurance process and the deterrence that exists, as well as in the actual transactions that are identified through the process.
I am probably being a bit pedantic, but on deterrence, if we do not know the scale of fraud because of a mix of error and pensioners not being notified in time, how do we estimate the deterrent effect? Who knows about the NFI and would say, “Right, I am not going to fraudulently make a claim because the NFI will pick up on it?” I am curious to understand how the deterrence works. I absolutely take the point about the assurance process and all that, but I am struggling to get my head around deterrence.
I understand and will bring in Martin McLauchlan in a moment. Fundamentally, the way in which the exercise works is that, because of GDPR and data protection requirements, all staff who work in an organisation must be informed that their data is being used as part of the exercise. Similarly, to go back to Tim Bridle’s example about benefits and Social Security Scotland, people who receive benefits are informed that their information will be used as part of the exercise and are told how it will be used and the purpose for which it will be used.
I accept your point. It is incredibly difficult to quantify the value of deterrence, because, fundamentally, you do not know how many people might have committed a fraud if they had not been alerted to how the exercise works. My comeback to that is that I would not want to test the waters by stopping the exercise in order to see the level of fraud that then occurred. Deterrence cannot be underestimated, but I accept that it cannot be quantified very easily.
It is exactly as John Cornett said about proving the counterfactual—we cannot put a number on it. We can say that there was a general acceptance that the risk of fraud occurring increased during the Covid pandemic. Counter-fraud professionals, of which I am not one, have developed what they refer to as a fraud triangle, which comprises pressure, opportunity and rationalisation.
There is a pressure not only on public finances but on individuals’ circumstances due to the ongoing cost of living crisis. The opportunity is that, in the environment now operating across individual public sector bodies, with better IT and better understanding, there is greater scope to commit fraud. It is not wide-scale, sophisticated fraud; it is perhaps opportunistic fraud in that people think, “Actually, I will try and claim something.” On rationalisation, we have seen in recent years that there is potentially a greater appetite and greater rationalisation along the lines of, “Well, it is only that one claim, so I will do it.”
We cannot talk through the deterrence but, as John Cornett rightly said, we would not want to be in a position where we were seen to withdraw the NFI as it stands. In terms of awareness, everyone who is employed by any body that is involved is directly notified about the NFI, because their data is entered.
That is helpful and I understand deterrence better. I understand that everybody is notified, so that is useful.
For example, we all receive an email from Audit Scotland saying that our details are being entered into NFI data matching, and that is standard practice for all 127 bodies.
On delivering the NFI, the report says:
“Two bodies were assessed as having fundamental issues with submission of datasets for matching”.
Which organisations were they? It appears that one is in local government and the other is in the colleges sector. What specific support or intervention is being proposed to them to help them deliver on their NFI arrangements?
10:30
Apologies, convener—my Gaelic is not very good, so I will say that the local government body is Western Isles Council. As you may well be aware, it was subject to a cyberattack a couple of years ago, which fundamentally disabled its financial systems. Because of that, it was not in a position to submit data.
I believe that the second body is Perth College; I do not know the details of why it has not been able to submit the data. Tim or Martin might have the detail on that.
I think that that was an accident of circumstance, which probably involved a change in the staff who were responsible. Perth College has put arrangements in place, and I have been liaising with it actively around submission for the next exercise. I believe that it was one of those unfortunate circumstances.
Thanks for that clarification. The report mentions that there were
“Two cases of dual full-time working”—
that is, someone having more than one full-time job—and
“Three cases of working in a secondary role while off sick from the main employer.”
I understand that more such cases were identified previously. Is there a risk of that increasing with more home working? Can you clarify who those individuals were working for? Were both the organisations that were being worked for covered by the national fraud initiative, or was it one organisation?
Again, Tim Bridle has the detail. However, it is important to highlight that someone simply having two jobs is not necessarily fraudulent. It can be entirely legitimate that a person works two jobs.
Yes, but we are talking about two full-time jobs.
Agreed. However, the challenge is to determine whether they are able to deliver those jobs. There is also a wider challenge around whether there is a health and safety risk involved in whatever work they might be engaged in. If somebody is a driver and is working two full-time jobs, does a health and safety risk come out of that?
Tim has the detail on the data matches and how that came through.
There will be an A and a B match for these people, but the A and the B will not always be both in Scotland—sometimes the B side will be in England or Wales. We have had one or two of those instances over the years. Essentially, though, they get counted only once, but it will be affecting two organisations.
Are the two organisations covered by the national fraud initiative?
Yes.
So there could be more cases where an individual is working for one organisation that is covered by the national fraud initiative, but also works for somebody else entirely. There can be a gap there.
Yes. That is another reason why we are keen to expand the data pool to include payrolls for housing associations and universities, for example.
There is nothing to stop somebody working for a private sector organisation—but I know that that is outwith the remit of what we are talking about.
I was going to say that there was a case from the previous exercise of someone having two full-time jobs with bodies in Scotland, another job with a council down south and two jobs in the private sector.
Well, they were very busy. I am glad that that was revealed by the audit—it is working effectively when that happens. As you said, we need to look at areas where we can extend it so that it can pick up more.
I have one more question, which is on the use of blue badges. The report says that 5,000 blue badge passes of people who had deceased were cancelled in 2024-25. In the case of bus passes, you were able to say how many times they had been used, but I imagine that that is difficult with blue badges. Is there any indication of how many times they may have been used?
Also on blue badges, I noticed that, in terms of outcomes, the financial impact had come down marginally. Has that 5,000 figure significantly changed? Is that comparable with previous years?
I think that the position is broadly comparable with previous years, and you are absolutely right that the challenge with blue badges is that we cannot estimate how many times they are used. Therefore, the calculation is a notional figure of how many times the blue badges may have been used, on a reasonable basis. I do not remember the detail, but it might be reasonable to assume that they are used once a week, for example. There is also the notional figure of, for example, how much a car park would have cost if the individual had paid, and that can vary quite considerably. Therefore, it is a best estimate of the number of fraudulent uses and the value of the transactions that have been forgone.
The primary challenge in relation to blue badges is that, even if a badge is cancelled, it is not recovered, so a cancelled badge can continue to be used. It is only when a badge expires that it becomes evident to a parking enforcement officer that it is being used inappropriately. There are a number of system weaknesses that are highlighted at a local level. Fundamentally, the blue badge figures are a best estimate. I think that Tim is a bit closer to that calculation than I am.
The numbers for the cancellation of blue badges remain fairly consistent—about 5,000 have been cancelled. The values that are attached to that and the levels of abuse are an estimate, and there is probably a range of reasonableness in relation to the estimate.
In relation to tax and welfare, where there is better evidence, 5 per cent is the figure that is often quoted for fraud rates, so it would not surprise me if, for example, 5 per cent of the blue badges that were cancelled were being used fraudulently. That would be a typical top end of the range of reasonableness, which would result in a financial value that is in line with what we have reported.
In fact, we have identified a lower rate of abuse for concessionary travel passes. The estimate for that might be at the bottom end of the range of reasonableness, so we might use 1 per cent for that, rather than 5 per cent. In essence, we apply the Public Sector Fraud Authority methodology, and the figures come from the system.
I understand that there is a limit to what you can do on the data. We have talked a lot about deterrence. If the numbers are remaining consistent, I think that deterrence needs to happen through enforcement as much as the data matching exercise.
We have no further questions, so I thank you for your extensive evidence on the national fraud initiative in Scotland in 2026.
We will suspend the meeting to allow for a change of witnesses.
10:38
Meeting suspended.
10:41
On resuming—