| Fraud type: |
Theft or sale of sensitive/ restricted documentation or information |
| Suggested controls: |
Controls over third party information held on computer should comply with the requirements of the Data Protection Act; staff should be informed of the rules; |
|
Official documentation should be held securely; |
|
Background checks on staff should be of an appropriate level, depending on the nature of the post held. |
|
Access to computer records should be logged and spot checks made to confirm that there were valid reasons for any unusual accesses. |