Fraud Risks in Public Sector Entities: A Conversation with Matt Laughlin
Public sector organizations are responsible for serving their communities while protecting the resources entrusted to them. With complex funding sources, decentralized operations, and evolving compliance requirements, fraud risk can arise in ways that are not always easy to spot. To better understand where risks commonly appear and how organizations can respond, we spoke with Mindy Piatz, Principal at Brady Martz.
Q: Why is fraud risk such an important topic for public sector entities?
Matt: Public sector organizations operate with a high level of public accountability. Taxpayers, grantors, boards, and other stakeholders expect funds to be used appropriately and transparently. At the same time, many entities are managing large transaction volumes, multiple programs, and limited staff capacity.
That combination can create pressure on internal processes. Fraud prevention is not about assuming something is wrong. It is about recognizing where vulnerabilities may exist and making sure the right safeguards are in place.
Q: Where do fraud risks most often appear?
Matt: Procurement and vendor management are common areas of concern. When there are many purchases, many approvals, or several departments involved, it can become harder to see patterns. That may create opportunities for improper payments, conflicts of interest, or issues within bidding and vendor selection processes.
Grant and program funding is another area to watch. Public sector entities often distribute funds to outside organizations or program partners. If monitoring is inconsistent, it can be difficult to confirm that dollars are being used as intended.
Payroll and benefits can also carry risk, especially in larger or decentralized organizations. Unauthorized overtime, inaccurate benefit claims, or employees who remain in the system after they should have been removed can all create financial exposure over time.
Q: How does organizational culture affect fraud prevention?
Matt: Culture plays a major role. Strong controls matter, but they work best when accountability is clear and leadership sets the right tone. Employees need to understand that policies are not just administrative steps. They are part of protecting public resources.
Smaller entities can face added challenges because one person may be responsible for several financial duties. When segregation of duties is limited, leadership and board oversight become even more important.
Q: What role does technology play?
Matt: Technology can be both a source of risk and a useful tool. Digital systems improve efficiency, but they also require proper access controls, user reviews, audit trails, and monitoring. If too many people have broad system access, or if access is not updated when roles change, risks increase.
On the other hand, technology can help organizations identify unusual activity. Data analysis does not have to be overly complex. Reviewing trends in vendor payments, payroll activity, expense reimbursements, or journal entries can help bring attention to items that may need a closer look.
Q: What practical steps can entities take to reduce exposure?
Matt: Start with the basics. Clearly define approval processes, document decisions, reconcile accounts regularly, and review who has access to financial systems. Periodic fraud risk assessments are also valuable because operations change over time. A control that worked well several years ago may not fit the organization today.
Training is another important step. Employees should know what fraud risks can look like and how to report concerns. Clear reporting channels, including anonymous options, can help concerns surface earlier.
Independent oversight also adds value. Internal reviews, board involvement, and external audits can help validate whether controls are working as intended and identify areas for improvement.
Q: What is the biggest takeaway for public sector leaders?
Matt: Fraud prevention should be viewed as an ongoing responsibility, not a one-time project. Public sector entities face a challenging environment, but proactive attention can make a meaningful difference.
By strengthening controls, improving visibility, and reinforcing accountability, organizations can better protect the resources they manage. For many entities, a thoughtful review of current practices is a good starting point for the conversation.
