The Department for Education (DfE) for England has published new guidance for schools, colleges and independent training providers to reduce the risk of fraud.

Fraud is a huge issue in the UK. In fact, the Education and Skills Funding Agency (ESFA)’s Annual report and accounts for 2024 revealed that it had taken, “effective and strategic approaches to identify and prevent £91 million in fraud and error, £32.4 million more than in 2022-23.” 1 This issue, of course, impacts the education sector – one full of sensitive and vulnerable data.

With this in mind, the DfE has published new guidance for schools on managing the risk of fraud. The guidance covers common types of fraud in the education sector, how to create a fraud risk management strategy and response plan, and information on reporting fraud.

Fraud in the education sector

The guidance identifies common types of fraud in the sector as theft, fictitious and falsification of invoices, and credit card and mandate fraud. 2 To manage the risk of fraud, it recommends that schools, colleges and independent training providers create a fraud risk management strategy and response plan, which are in line with the ‘responsibilities and expectations of public sector organisations in relation to fraud’. 2 Whilst the guidance lists strategies for creating an effective risk management strategy, it clearly notes that the most effective strategy is to focus on prevention.

The documentation also refers readers to Indicators for potential fraud: a generic checklist for providers which an establishment can use to help them identify potential fraud. This is split into sections covering:

  • personal flags for fraud, such as, ‘Does anyone have evidence of an expensive lifestyle (such as cars or trips) that seems disproportionate to their income?’,
  • organisation flags, such as, ‘Does the organisation have a for-profit component?’,
  • weakness in internal controls, such as, ‘Is there a general lack of transparency about how the organisation works and implements procedures and controls?’,
  • transactional indicators, such as, ‘Are there specific transactions that typically receive minimal oversight?’,
  • methods used to commit or conceal fraud, such as, ‘ Are there employee issues with auditors, e.g., a refusal or reluctance to provide information or hand over documents?’,
  • recordkeeping, banking and other red flags, such as, ‘Are there transfers to or from any type of holding or suspension account?’ 3

The guidance notes that a fraud response plan will have actions proportionate to the risk faced, and lists typical things a plan will involve, such as, ‘developing and promoting anti-fraud culture’ and ‘establishing cost-effective internal systems of control to prevent and protect fraud’.  2

Cyber security

Within the guidance, there is a specific section on cyber crime and cyber security, as cyber breaches are prevalent in schools and can cause them to be victims of fraud.

So, how common is it? The Cyber security breaches survey 2024: education institutions annex reported the percentage of schools (by type) that had reported a cyber attack or breach within 12 months (2023-2024) as:

  • 52% of primary schools
  • 71% of secondary schools
  • 86% of further education colleges
  • 97% of higher education institutions

It was also noted that while primary schools are close to a ‘typical business’ in terms of cyber attacks/breaches, all other education institutions are more likely to have identified a breach or attack in 12 months than the average UK business. 4

In the Reducing fraud in the education sector guidance, it notes that “Organisations should be vigilant and proactive in relation to cybercrime and have cyber security arrangements in place” and refers readers to the Cyber security standards for schools and colleges documentation.

Read the full Reducing fraud in the education sector guidance

References

  1. Education and Skills Funding Agency (2024) ‘Education and Skills Funding Agency: Annual report and accounts’. Available at: https://assets.publishing.service.gov.uk/media/66bb39e10808eaf43b50e0d0/ESFA_Annual_Report_and_Accounts_2023_to_2024.pdf (Accessed: 02 July 2025)
  2. GOV.UK (2025) ‘Reducing fraud in the education sector’. Available at: https://www.gov.uk/guidance/reducing-fraud-in-the-education-sector (Accessed: 02 July 2025)
  3. GOV.UK (2025)  ‘Indicators for potential fraud: a generic checklist for education providers’. Available at: https://www.gov.uk/government/publications/indicators-of-potential-fraud-learning-institutions/indicators-for-potential-fraud-a-generic-checklist-for-education-providers (Accessed: 02 July 2025)
  4. GOV.UK (2024) ‘Cyber security breaches survey 2024: education institutions annex’ Available at: https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/cyber-security-standards-for-schools-and-colleges (Accessed: 02 July 2025)

Author

  • Kat Cauchi

    Kat is the former editor of R.I.S.E. Magazine. She is the chair of the BESA Women’s Educational Suppliers Network, a Global Equality Collective member, InnovateHer ambassador and TechUpWomen Mentor. She is a also a 2023 #TechWomen100 award winner and 2022 Nexus Education award winner.

    View all posts