In Ireland, a new audit has found that unapproved salary rates could be paid to Health Service Executive (HSE) staff over an “extended period of time”, while potential “irregularities” in the wider organisation may not be identified and acted upon, MSN reports.
The findings were released to the Irish Examiner under the Freedom of Information Act. This was an internal audit of fraud risk assurance within HSE payroll (which issued payments worth €8.5bn in 2023) from November 2025.
It reportedly warned of the risk of financial loss and reputational damage to the organisation arising from “potentially systemic” issues.
In addition, it identified that, while not technically a fraudulent loss, overpayments to staff totalling €12.7m in 2023 were an “upward trend of concern” and could mean the full recovery of monies is not possible.
“Many of the controls are appropriate, however some specific fraud assessment is reactive, and many mitigation controls are implicit rather than explicit,” the audit found.
“This requires improvement, however much of this crosses organisational boundaries between HR, Finance, Line Management and ICT, and needs a holistic approach to be effective.
“Fraud risk within payroll processes is heightened and inherently a high risk, as the large sums involved make it a significant target for theft and fraud.”
It reportedly found that the HSE does not incorporate a fraud risk assessment in its approach to fraud risk management, while there is no “risk and controls matrix” of the payroll process.
The findings stated that such a matrix ensures someone is always responsible for mitigating risk in an organisation and, in the absence of clear accountability and ownership of controls, there is the “potential for fraud risks being overlooked”.
The audit also recommended that the testing of plans for an IT systems failure needs to be a routine process. It said an over-reliance on untested plans heightens the risk of service interruption and criminal exploitation.
“There is no programme within HSE payroll tailored to the fraud risk response expected from staff and aligned to HR and other procedures,” the audit said.
The audit reportedly concluded that the level of assurance that could be given to management regarding the adequacy and effectiveness of the governance, risk management, and internal control systems in this area was “limited”.
In response to the audit, the HSE said payroll is one of the largest and most complex payment systems in the State and is "proactively responding to the highlighted risks".
Source: MSN
(Quotes via original reporting)
In Ireland, a new audit has found that unapproved salary rates could be paid to Health Service Executive (HSE) staff over an “extended period of time”, while potential “irregularities” in the wider organisation may not be identified and acted upon, MSN reports.
The findings were released to the Irish Examiner under the Freedom of Information Act. This was an internal audit of fraud risk assurance within HSE payroll (which issued payments worth €8.5bn in 2023) from November 2025.
It reportedly warned of the risk of financial loss and reputational damage to the organisation arising from “potentially systemic” issues.
In addition, it identified that, while not technically a fraudulent loss, overpayments to staff totalling €12.7m in 2023 were an “upward trend of concern” and could mean the full recovery of monies is not possible.
“Many of the controls are appropriate, however some specific fraud assessment is reactive, and many mitigation controls are implicit rather than explicit,” the audit found.
“This requires improvement, however much of this crosses organisational boundaries between HR, Finance, Line Management and ICT, and needs a holistic approach to be effective.
“Fraud risk within payroll processes is heightened and inherently a high risk, as the large sums involved make it a significant target for theft and fraud.”
It reportedly found that the HSE does not incorporate a fraud risk assessment in its approach to fraud risk management, while there is no “risk and controls matrix” of the payroll process.
The findings stated that such a matrix ensures someone is always responsible for mitigating risk in an organisation and, in the absence of clear accountability and ownership of controls, there is the “potential for fraud risks being overlooked”.
The audit also recommended that the testing of plans for an IT systems failure needs to be a routine process. It said an over-reliance on untested plans heightens the risk of service interruption and criminal exploitation.
“There is no programme within HSE payroll tailored to the fraud risk response expected from staff and aligned to HR and other procedures,” the audit said.
The audit reportedly concluded that the level of assurance that could be given to management regarding the adequacy and effectiveness of the governance, risk management, and internal control systems in this area was “limited”.
In response to the audit, the HSE said payroll is one of the largest and most complex payment systems in the State and is "proactively responding to the highlighted risks".
Source: MSN
(Quotes via original reporting)