1. Vision and Purpose
1.1 Our vision is:
“To minimise financial losses from fraud, bribery, corruption and error, protecting vital resources dedicated to frontline patient care. This will be achieved through a blended delivery model underpinned by the four core strategic pillars of Understand, Prevent, Respond and Assure”.
1.2 Our purpose is to:
“Lead and coordinate counter-fraud efforts to safeguard the health sector, by embedding practical and proportionate counter fraud-by-design principles into new delivery services and critical programmes of change”.
1.3 As a counter fraud organisation, we are dedicated to protecting the integrity of the healthcare systems in England.
Fraud (Internal and External)
In line with NHSCFA’s goal to protect the NHS from fraud, bribery and corruption, the organisation has no tolerance for any and all forms of fraudulent activity. NHSCFA is committed to the proactive prevention, robust detection, thorough investigation and effective enforcement of anti-fraud measures.
Risk is only tolerated where it directly supports intelligence gathering and proactive engagement. Our strategic intelligence and data analytics initiatives will accept minimal risk when the potential outcomes significantly strengthen NHSCFA’s ability to detect, disrupt and prevent fraud.
Bribery
NHSCFA has a no tolerance approach to bribery fully aligned with the Bribery Act 2010. Any act or perception of offering, giving or receiving bribes is strictly prohibited. The organisation proactively promotes a strong culture of integrity with active learning initiatives to raise awareness among staff and stakeholders. This includes ensuring supplier integrity and adherence to established governance standards across the health sector.
Corruption
Our risk appetite for corruption is categorically averse, reflecting the significant reputational, financial and operational harm corruption poses to public trust and its adverse impact on healthcare delivery. We actively engage in raising awareness, improving system controls, embedding a culture of transparency and accountability across the NHS and wider healthcare sector. In doing so, we support the creation of an environment where corrupt practices are identified and decisively dealt with.
Strategic Innovation (AI Tools, Data Analysis)
To remain effective against increasingly sophisticated fraud threats, NHSCFA embraces innovation through advanced technologies such as AI and data analytics. A ‘Cautious’ to ‘Open’ risk appetite is applied to strategic innovation. Each initiative is subject to comprehensive risk assessment and is governed by principles of ethics, agility and security to ensure responsible deployment and operational integrity.
Reputational Risk (Counteracting Fraud, Bribery & Corruption)
NHSCFA acknowledges the reputational sensitivity inherent in its counter-fraud work. The organisation maintains a low tolerance for reputational risk, particularly in relation to sensitive activities likely to generate closer public, stakeholder or regulatory scrutiny. To preserve trust and credibility, all counter-fraud initiatives are underpinned by clear communication strategies and robust oversight and assurance mechanisms.
Error
This refers to unintentional losses or control breaches arising from process failures, human mistakes, or system limitations rather than from deliberate fraudulent or malicious action. We understand that error is managed not eliminated through proportionate controls, adaptive systems and ongoing reviews, allowing fraud prevention and counter‑fraud activities to balance effectiveness and efficiencies.
2. Introduction
2.1 The Department of Health and Social Care Anti-Fraud Unit (DHSC AFU) is responsible for setting the overarching counter fraud policy and strategy across the entire health group in England. The NHS Counter Fraud Authority (NHSCFA) reports to its Board and is ultimately accountable to the DHSC AFU for the effective delivery of this strategy.
2.2 Risk management is a vital part of NHSCFA’s governance framework, underpinning the achievement of the organisation’s strategic themes and objectives. By identifying and addressing potential threats and opportunities, effective risk management enhances the likelihood of successful outcomes and safeguards the organisation’s reputation and long-term viability.
2.3 NHSCFA’s organisational strategy outlines the current approach to tackling fraud, corruption and error across the NHS and the wider health group. Delivering on its overarching themes and objectives requires a risk appetite that supports both the pursuit and effective management of inherent risks and opportunities.
2.4 NHSCFA takes its responsibilities to stakeholders seriously, viewing risk management as both a key element of effective governance and a critical means of fulfilling its obligations to partners and key stakeholders.
2.5 The NHSCFA’s Risk Management Policy provides a structured framework for the effective identification, assessment, and management of risk. It aims to maximise opportunities while minimising averse risks in pursuit of the organisation’s strategic objectives. The probability and impact risk scoring matrix, is shown at Appendix A.
2.6 NHSCFA’s Risk Appetite Statement outlines the organisation’s tolerance for risk across key strategic areas, reflecting the level of risk it is willing to accept in support of informed decision-making.
3. Overall Risk Appetite
3.1 NHSCFA’s Board, management, and staff will consider the organisation’s risk appetite in both strategic and operational decision-making.
3.2 The strategic vision and objectives outlined above will influence how the organisation accepts risk in these specific areas, in proportion to the potential benefits.
3.3 The chart at Appendix B is adapted from HM Treasury’s practitioner’s guide and provides a visual reference of NHSCFA’s overall organisational risk appetite ranging from Averse to Hungry across each of its identified risk categories.
3.4 Overall, NHSCFA maintains an ‘OPEN’ risk appetite. However, it recognises that in certain strategic corporate risk areas, the level of risk it is willing to accept may vary, being higher or lower depending on the specific activity and context.
3.5 The key challenges in achieving an appropriate balance include:
- ensuring ethical and effective governance, with responsible management and oversight of resources
- enabling innovation and seizing opportunities, while avoiding unnecessary bureaucracy; and
- preventing a risk-averse culture that stifles innovation, by promoting the proper assessment and management of risk to support informed decision-making.
4. Risk Framework
4.1 Good risk management practice recommends that organisations define their risk appetite at a granular level, aligned with the nature of their activities. This Risk Appetite Statement outlines the level of risk NHSCFA is willing to seek or accept in pursuit of its strategic objectives.
4.2 In setting priorities, NHSCFA places the highest importance on avoiding risks related to compliance and the health and safety of its staff. For example, the organisation may acquire and analyse bulk datasets, provided this does not expose the organisation or individuals to undue compliance risks. This approach enables NHSCFA to carry out its functions effectively, which is essential to it achieving its strategic objectives.
4.3 Therefore, a balanced assessment of risk is essential, as there are often risks associated with both taking action and non-action. In some cases, the 'do nothing' approach may present an even greater risk.
4.4 Risks are managed in line with the organisation’s Risk Management Policy. Operational (non-corporate) risks are reviewed by the Leadership Team (LT) and escalated to the Senior Management Team (SMT) when they are deemed to potentially warrant reclassification as corporate risks. Corporate and emerging risks are discussed during the Risk Register Review Group meeting, with identified recommendations actioned by the SMT. These are then subsequently reviewed and subject to challenge at the Executive Assurance Panels.
4.5 Responsibility for reviewing and approving the NHSCFA’s Risk Appetite Statement rests with the Board through the Audit, Risk and Assurance Committee.
5. Risk Approach
5.1 NHSCFA aims to minimise its exposure to risks related to regulatory and legal compliance, while accepting and in some cases encouraging a greater degree of risk in pursuit of its strategic objectives. There can be a danger when focusing on negative risks that the organisation will sometimes miss associated opportunities. Where positive risks occur, these will be managed as an opportunity with priority given to actions most likely to achieve successful outcomes.
5.2 The organisation recognises that its risk appetite varies depending on the nature of the activity. Risk acceptance is contingent on a clear understanding of both potential benefits and associated risks before any programme or project is approved. Where necessary, appropriate and proportionate risk mitigation measures must be in place.
5.3 Appendix C charts NHSCFA’s current overarching strategic risk areas and the corresponding tolerance levels, representing the agreed acceptable deviations from the organisation’s stated risk appetite.
6. Fraud Risk Statement
6.1 NHSCFA has no tolerance for fraud, bribery or corruption perpetrated by our people. The organisation takes all allegations extremely seriously and has robust anti-fraud and public interest disclosure policies in place. These are reinforced by the Standards of Business Conduct policy and the organisation’s Standing Financial Instructions which requires all of our people to declare any business and other interests, additional employment, gifts or hospitality they or a family member may have, which are or may be relevant to the work of the NHSCFA or the individuals work within the organisation.
6.2 NHSCFA is firmly committed to complying with all relevant legislation, regulation and sector standards as well as its own internal policies and corporate governance principles. A formal fraud risk appetite statement defines the level of fraud, bribery and corruption the organisation is willing to tolerate in pursuit of its objectives. NHSCFA has ‘Minimal’ appetite for any activity that could lead to financial loss, reputational harm, or compromise the integrity of its functions. The risk to fraud, bribery and corruption is minimised through stringent control measures.
7. Responsibility for implementation & review of NHSCFA’s Risk Appetite
7.1 The Board is responsible for providing strategic leadership to the organisation and ensuring accountability to Parliament and the public for the effective delivery of NHSCFA’s functions.
7.2 The Senior Management Team (SMT) is responsible for setting and overseeing the delivery of the organisation’s strategic aims and business priorities. It also ensures the establishment and maintenance of robust governance, including an effective risk management process and adherence to this Risk Appetite Statement.
7.3 Risks recorded in the risk register reflect both internal and external source factors and are reviewed regularly. The register is also updated in response to significant changes in policies, organisational structure, functions, or the broader operating environment.
The Senior Management Team (SMT) is responsible for risk register entries related to the strategic and corporate risks faced by the organisation, along with the control frameworks in place to mitigate them.
Unit Business Leads are accountable for recording and managing risk register entries associated with the day-to-day operational risks within their respective divisions, including the relevant mitigation controls.
Project, Programme Managers, and Senior Responsible Owners (SROs) are responsible for identifying and managing risks related to corporate projects, programmes, and portfolios, along with their associated control frameworks.
Both the SMT and Unit Business Leads are responsible for maintaining risk register entries in alignment with this Risk Appetite Statement, ensuring the appropriate escalation of risks that fall outside the stated appetite or agreed tolerance levels for specific activities.
7.4 Confirmation, review & Communication
This Risk Appetite Statement has been reviewed and approved by the Board and the Audit, Risk and Assurance Committee (ARAC).
It is reviewed at least annually and is published on both the external website and the internal staff intranet.