SmartSuite for the Fraud Risk Manager
The Fraud Risk Manager owns the fraud risk assessment and the anti-fraud programme: identifying fraud schemes the organisation is exposed to, mapping preventive and detective controls, overseeing investigations and reporting fraud losses and trends to the risk and audit committees.
What you own
- Conduct and maintain the enterprise fraud risk assessment
- Map fraud schemes to preventive and detective controls
- Operate the anti-fraud policy, training and reporting channels
- Oversee fraud investigations and case management
- Analyse fraud losses, trends and control gaps
- Report fraud risk and investigation outcomes to the audit and risk committees
Where the role sits
Each name opens that role's page.
Reports to
Direct reports
Works closely with
GRC processes
The shared GRC process map, highlighted for this role.
Owns
accountable for the process
Touches
contributes or approves
Depends on
consumes its output
How SmartSuite helps, suite by suite
Each card is the persona record from that suite's Users tab.
Suites that serve this role
How SmartSuite supports this role
Risk management. Holds the fraud risk assessment as a scored register of schemes, likelihood and impact, linked to the controls that address each one.
Issues and actions. Manages investigations as case records with evidence, tasks and confidential access, and tracks corrective actions to closure.
Internal audit. Shares fraud control results with internal audit so testing and investigations draw on the same records.
Reporting. Produces fraud loss and trend reports for the audit and risk committees from case data.
Industry reference
The COSO and ACFE Fraud Risk Management Guide (2nd edition, 2023) is the reference: a governance policy, a fraud risk assessment, preventive and detective controls, investigation and monitoring. COSO's 2013 framework makes fraud risk assessment an explicit principle (Principle 8), so SOX programmes test it.
Sector rules add teeth. Banks file suspicious activity reports under the Bank Secrecy Act and are examined against FFIEC guidance; healthcare organisations face the False Claims Act and OIG enforcement; US federal programmes follow GAO's Fraud Risk Management Framework and the Payment Integrity Information Act; payment and technology firms meet PCI DSS and card-scheme fraud rules.
In their words
Related roles
See SmartSuite for your role
Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.





