Helping you prosper
Fraud rarely announces itself. It arrives as an ordinary-looking email, a convincing phone call or an invoice that looks just close enough to the real thing to pass an inbox glance. For academy trusts handling public money on behalf of children and communities, the consequences of getting caught out go well beyond the financial loss itself.
The scale of the problem nationally is significant. The Public Sector Fraud Authority estimates that fraud and error costs taxpayers somewhere between £39.8 billion and £58.5 billion a year, and the Department for Education (DfE) have recently sharpened their focus on the education sector specifically, publishing a fraud awareness good practice guide. Alongside it, DfE's counter-fraud team has flagged a live scam currently doing the rounds in education settings: fraudsters posing as a bereaved spouse offering to donate a piano, before persuading staff to pay upfront courier or delivery fees for an instrument that never arrives.
It's a small example, but it illustrates exactly how these attempts work - an emotionally plausible story, a modest and unremarkable payment request, and enough urgency to bypass a moment's scrutiny.
Why academy trusts are a target
Academy trusts sit in an unusual position: publicly funded, charitable, often multi-site and reliant on a wide network of suppliers, contractors and staff across schools that may have very different levels of financial sophistication.
The DfE guidance groups the main risks trusts should have on their radar:
- Invoice and mandate fraud - a fraudster poses as a genuine supplier and asks for payments to be redirected to a new bank account, often with manufactured urgency.
- Phishing - impersonation via email, text, phone call or fake QR code, frequently aimed at harvesting passwords or banking credentials, or impersonating a trust leader to authorise a payment.
- Malware and ransomware - increasingly aimed at organisations holding large volumes of sensitive data on children, and particularly likely to strike during holiday periods when staffing (and vigilance) is thinner.
- AI-enabled fraud - deepfake audio and video impersonating trust leaders, cloned voices used to authorise payments, and increasingly convincing forged certificates and documents.
- Certificate and qualification fraud - false or altered qualifications presented by staff or learners, with safeguarding as well as financial implications.
- Internal fraud - falsified expenses, misuse of assets, or collusion linked to undeclared conflicts of interest, which can be harder to detect precisely because the person involved understands the trust's own controls.
- Procurement fraud - collusive bidding, duplicate or inflated invoices, and weaknesses in tender processes.
What trustees and finance teams should be doing
The good news is that none of this requires reinventing a trust's governance from scratch. The DfE guidance is built around a simple structure that maps well onto existing academy trust financial management: understand the risk, prevent it, detect it and know how to report it.
Practical steps worth prioritising include:
- Naming ownership. Fraud prevention should sit with specific, named roles. Whether that's the finance director, the audit and risk committee or a designated counter-fraud lead.
- Refreshing the counter-fraud policy. A policy is only useful if it reflects current threats. Trusts should review whether theirs covers emerging risks like AI-enabled impersonation and QR code scams.
- Reinforcing payment verification. Any request to change supplier bank details should be verified by phone, using a number the trust already holds on file.
- Testing the whistleblowing route. Staff need a policy they actually know exists, understand how to use and trust will protect them if they raise a concern.
- Building fraud awareness into routine training. This is not a one-off induction topic. Regular refreshers, particularly around AI-driven and invoice fraud, help staff recognise the warning signs before a payment is made.
A sharper legal backdrop
There is also a compliance dimension trustees should not overlook. Since September 2025, the Economic Crime and Corporate Transparency Act 2023 has introduced a corporate offence of failing to prevent fraud, applying to large organisations meeting two of three thresholds:
- more than 250 employees
- turnover above £36 million
- assets above £18 million.
Some of the larger multi-academy trusts will already meet this threshold and others are likely to grow into it as consolidation across the sector continues. Having demonstrably reasonable fraud prevention procedures in place is now not just good governance but also a legal safeguard.
The bottom line
Fraud prevention in the academy sector is not about assuming the worst of colleagues or suppliers, but about making sure a trust's controls are strong enough that an honest mistake, a moment of pressure or a convincing impersonation doesn't turn into a loss of public money intended for children's education.
The next step
If you would like support reviewing your trust's counter-fraud framework or internal controls, please get in touch with Jack Wilkinson or your usual UHY academy adviser.