Strategies for Detecting University Procurement Card Fraud

University procurement cards give staff a practical way to purchase low-value goods, travel items, emergency supplies, and specialised services. They also create a large stream of transactions that can be difficult to review manually. When purchasing activity spans several campuses, research units, hospitals, accommodation sites, and affiliated agencies, weak signals can remain hidden in otherwise legitimate expenditure.

A strong detection programme combines policy, data, staff awareness, and disciplined investigation. The objective is not to block ordinary purchasing or burden cardholders with unnecessary approvals. It is to identify unusual behaviour early, distinguish errors from deliberate misconduct, and give finance leaders reliable evidence for corrective action.

Control area Useful detection signal Practical response
Transaction monitoring Repeated purchases just below approval limits Review split transactions and related suppliers
Merchant analysis Unusual merchant category or high-risk retailer Confirm business purpose and delegated authority
Timing and location Weekend, public holiday, or distant transaction Compare with travel, roster, and event records
Supplier review Duplicate vendors, altered bank details, or shared addresses Validate supplier identity and procurement records
Cardholder behaviour Sudden spending growth or new categories Apply temporary review and targeted education
Exception management Recurring overrides or missing receipts Escalate patterns rather than isolated mistakes

Map The University’s Exposure

The first step is to understand how procurement cards are used across the institution. A metropolitan campus in Melbourne may have different spending patterns from a regional campus near Townsville or a research station outside Perth. Catering, fieldwork, laboratory supplies, student services, maintenance, and interstate travel each produce different merchant and timing profiles.

Create a risk map that records cardholder roles, spending limits, transaction volumes, merchant categories, approval pathways, and system integrations. Include cards issued to executive offices, faculties, libraries, accommodation operations, sporting units, and project teams. This makes it easier to identify where the institution has concentrated exposure rather than treating every cardholder as having the same risk.

Risk assessments should cover both external fraud and internal misuse. A compromised card number may generate several rapid online transactions, while an employee using the card for personal purchases may spread expenditure across small local retailers. Supplier collusion, false refunds, duplicate invoices, and transactions divided to avoid a threshold require different analytical methods.

Create A Reliable Data Foundation

Fraud analytics are only as useful as the underlying data. Finance teams should bring together card transactions, receipts, purchase orders, expense claims, travel bookings, employee records, supplier master files, delegation registers, and leave information. Consistent identifiers are essential. A supplier name that appears in five formats can prevent matching and conceal repeated activity.

The data model should preserve transaction date, posting date, merchant location, currency, GST treatment, merchant category code, cardholder, cost centre, project code, approver, receipt status, and exception history. Australian institutions should account for AUD transactions, GST-inclusive pricing, and overseas purchases that may be converted by the card provider. A purchase made in Brisbane may post a day later through a Sydney-based payment processor, so location rules need to allow for settlement behaviour.

Data quality controls deserve regular attention. Missing cost centres, generic descriptions such as “supplies”, inconsistent supplier numbers, and manually edited receipt records reduce confidence in alerts. Assign ownership for correcting these fields and publish data-quality measures alongside fraud indicators. A clean audit trail also supports reviews under institutional policy and relevant public-sector obligations.

Apply Layered Analytics

No single rule can identify every form of procurement card abuse. Begin with transparent rules that finance staff can explain, such as transactions above a defined amount, repeated purchases from the same merchant, activity outside normal working hours, or spending at retailers unrelated to a cardholder’s role. Rules should be tailored by department, because a facilities team may legitimately purchase from hardware stores while an academic office may not.

Add behavioural analysis to identify changes over time. A cardholder who normally spends modestly on office materials but suddenly records frequent electronics purchases warrants attention, even when every individual transaction falls below the approval threshold. Peer comparisons can reveal unusual activity by comparing a cardholder with people in similar roles, campuses, or cost centres.

Machine learning can support prioritisation, but it should not replace judgement. Clustering, duplicate detection, and anomaly scores are valuable when the institution can explain the factors behind an alert. A high score may reflect a legitimate conference, field trip, or emergency response. Analysts should see the transaction context, related purchases, supplier history, and previous outcomes before deciding whether escalation is appropriate.

Strengthen Cardholder And Approver Controls

Prevention improves detection because clear rules make exceptions easier to recognise. Cardholders should receive role-specific training on allowable expenditure, receipt standards, tax information, split transactions, personal benefits, gift cards, travel costs, and disputed purchases. Short refreshers linked to actual institutional examples are more useful than a policy document issued once at induction.

Approvers need comparable guidance. Approval should demonstrate that the purchase was necessary, permissible, correctly coded, and supported by evidence. A manager who approves every transaction within seconds may create a control weakness, even without dishonest intent. Approval logs should therefore record timing, delegation status, and whether the approver had a conflict of interest.

Use sensible limits and merchant restrictions where the card programme allows them. Online purchases, cash withdrawals, fuel, alcohol, gambling, and gift cards may require special treatment or blocking. Temporary limits can support overseas travel, research expeditions, or major events without leaving a broad increase in authority permanently active. Promptly cancel cards when staff leave, change roles, or move to a position without purchasing responsibility.

Detect Patterns That Manual Reviews Miss

Fraudsters often rely on transactions looking ordinary in isolation. A sequence of purchases just below an approval limit, several refunds followed by new charges, or purchases from different stores sharing a delivery address may reveal intent. Link analysis can connect cardholders, suppliers, approvers, addresses, phone numbers, bank details, and project codes.

Time and geography provide additional context. Tap-and-go spending is routine in Australia, and contactless payments through mobile wallets can make legitimate low-value purchases frequent and fast. A cluster of transactions in Sydney during a documented conference may be reasonable, while simultaneous physical and online activity from different locations may require review. Public holidays, weekends, and university closure periods should be treated as risk signals rather than automatic proof of misconduct.

Create an alert triage process with defined severity levels. A missing receipt may be a low-level compliance issue, while suspected personal use, collusion, or supplier manipulation should receive urgent attention. Record the reason for each decision, including cleared alerts. This prevents repeated investigation of known legitimate patterns and helps improve detection rules over time.

Investigate Fairly And Protect Information

An alert is an indication, not a finding. Investigators should gather the receipt, business purpose, purchase request, delivery evidence, approval trail, relevant policy, and any connected transactions. Give the cardholder an opportunity to explain unusual activity, particularly where travel, flexible work, fieldwork, or emergency purchasing may affect normal patterns.

Investigations should follow documented procedures for evidence preservation, interviews, escalation, repayment, disciplinary action, and referral to law enforcement where appropriate. Keep responsibilities clear between finance, internal audit, human resources, procurement, information security, and legal advisers. A consistent process reduces the risk of selective enforcement and supports procedural fairness.

Personal information must be handled carefully. Australian universities should consider the Privacy Act 1988, the Australian Privacy Principles, applicable state or territory requirements, and the Notifiable Data Breaches scheme when monitoring or sharing transaction data. Access should be limited by role, retention periods should be defined, and dashboards should avoid exposing unnecessary employee or supplier details.

Govern Suppliers And Australian Procurement Context

Supplier controls are central to card fraud detection. Screen for duplicate Australian Business Numbers, shared addresses, unusual changes to bank details, inactive or newly created vendors, and relationships between suppliers and university staff. Match card transactions against contracts and preferred supplier arrangements, while allowing documented exceptions for regional communities and specialist research needs.

Local procurement realities should shape the rules. A campus in Adelaide may use small local businesses that do not appear in a national supplier catalogue, while a remote Northern Territory site may depend on a limited number of vendors. A strict “unapproved supplier” rule could generate noise and discourage legitimate regional purchasing. A better approach checks business purpose, value, frequency, and supporting evidence.

Public universities also operate within different state and Commonwealth frameworks. Procurement teams may need to align monitoring with institutional delegations, state purchasing directions, the Commonwealth Procurement Rules where relevant, and obligations under the Modern Slavery Act 2018 for entities within scope. GST records, tax invoices, supplier onboarding, and fair treatment of vendors should be connected to the fraud-control environment rather than handled as separate administrative tasks.

Measure Results And Build Shared Capability

Senior business officers need measures that show whether controls are working. Track confirmed fraud, prevented losses, recovery amounts, alert volumes, false-positive rates, investigation duration, receipt compliance, card cancellations, and repeat findings. Segment results by faculty, campus, merchant type, and cardholder group to identify where training or control redesign will have the greatest effect.

Review thresholds at least annually and after significant events, such as a new card provider, finance-system migration, remote-work expansion, or major procurement change. Australian institutions should test rules against seasonal activity around semester starts, graduation ceremonies, orientation weeks, and end-of-financial-year purchasing. These periods often create legitimate spending surges that can distort static thresholds.

Peer exchange strengthens capability. Finance, procurement, internal audit, technology, and institutional research teams can share anonymised scenarios, control libraries, and lessons from completed investigations. Professional associations and cross-institution networks provide a practical setting for comparing approaches without exposing confidential employee or supplier information. The strongest programmes evolve as a community of practice, rather than relying on one compliance officer or one analytics dashboard.

A university procurement card programme should make legitimate purchasing efficient while making misuse difficult to conceal. Establish a cross-functional working group, inventory the available data, select a manageable set of high-value detection rules, and pilot them with one faculty or campus. Use the results to refine alerts, train cardholders, and create a repeatable reporting cycle for finance and audit committees. Consistent action turns transaction data into a durable safeguard for public funds and institutional trust.