Most of the fraud that hits early childhood education and care services is preventable. The controls that prevent it are ordinary and inexpensive, and they don’t require finance expertise to put in place.
The reason these controls are so often missing has less to do with anyone’s competence than with the structure of the sector itself.
Why ECEC services sit in a particular danger zone
Fraud risk grows with the distance between the person handling money and the person who genuinely cares about how it’s spent.
In a small owner-operated organisation, those are often the same person. The owner sees everything. As soon as you grow beyond that point, the gap opens up.
Most ECEC operators sit squarely in that gap. Single-centre not-for-profits with volunteer boards. For-profit operators running two to ten centres. Too big for one person to oversee every transaction, but too small to have formal financial controls in place.
Add the specifics of the sector, including volunteer treasurers, short tenures and boards reviewing by exception rather than scrutiny, and you have an environment where fraud is easier than it should be.
The 7 most common fraud types
Most of the fraud risk in the sector falls into seven categories:
- Access and identity fraud. A compromised email or system login used to approve transactions without the account holder’s knowledge.
- Payroll fraud. Unauthorised payroll changes such as inflated hours, fictitious employees, or pay rises that no-one approved.
- Payment redirection. Bank account details changed on legitimate invoices, so payments flow to the fraudster instead of the supplier.
- Fictitious invoices. Invoices from suppliers that don’t exist, approved through a weak process.
- Expense and card fraud. Personal purchases coded as business expenses, often kept small to avoid scrutiny.
- Cash theft. Money collected at fundraising events going missing before it’s counted and recorded.
- Subsidy misrepresentation. Attendance or enrolment data manipulated to inflate CCS claims or misrepresent grant acquittals.
AI has made several of these harder to detect. The phishing email full of typos is a thing of the past. So is the “obviously fake” invoice. Voice cloning means a familiar voice asking for an urgent payment can no longer be taken fully at face value.
The good news: the controls that work against traditional fraud also work against the AI-enhanced version.
The 7 fraud protection shields
These are simple controls that, in combination, prevent the vast majority of fraud.
1. Review the accounts regularly
Almost all fraud flows through a bank account. If your accounts reconcile properly each month, every transaction is recorded, and unusual entries become visible. Regular review is also one of the strongest deterrents available.
2. Use two-factor authentication on everything
Email is the most critical system to protect. A compromised email becomes a master key. It can be used to reset passwords across banking, accounting, payroll and cloud storage.
3. Approvers must see what they approve
A treasurer being asked to approve “$2,400 to XYZ Pty Ltd” without seeing the actual invoice cannot approve it safely. Modern tools like Xero, ApprovalMax and Dext make it easy for the source document to travel with the payment at every stage.
4. Control bank account details tightly
Two layers of protection here. First, limit who has system permission to change supplier and employee bank details. Second, treat any emailed request to change a bank account as a verification trigger. Call back using a number you already have on file, not the one in the email.
5. Separate recording from approving
The person entering and uploading bills should not be the person approving them at the bank. This is the single most fundamental fraud control, and the one auditors look for first.
6. Get the right insurance
Fraud risk insurance isn’t expensive. The catch sits in the fine print. Standard cyber crime cover often excludes social engineering, including the invoice redirection fraud that’s currently the most common attack on ECEC services. Coverage limits are often too low for the size of the organisation. And insurers typically only pay out if you’ve already got 2FA and out-of-band verification in place.
7. Manage cash at events properly
Cash is the hardest transaction type to recover if it goes missing. Eliminate it where you can, using EFTPOS or online payment platforms. Where cash is unavoidable, like fetes, sausage sizzles and raffles, apply the two-person rule at the count and sign-off.
If you ever do suspect fraud
Three things matter from the moment you suspect something is wrong.
Don’t confront the person immediately. It feels like the right thing to do but it almost never is. There is a lot to think through first.
Preserve the evidence before you cut access. Get copies of documents and emails into somewhere they can’t be deleted. Cutting off system access is a clear signal to the person that they’re under investigation, so do the documentation work first.
Get an accountant and a lawyer involved early. They bring different lenses. The accountant helps you trace what happened and stop further loss. The lawyer guides you through your obligations as an employer, which matter a great deal if the suspect is on staff. And contact your insurer immediately, because mishandling the early stages can give them grounds to fight a claim later.
The honest takeaway
You can’t protect against every sophisticated fraud. But the ordinary controls in this article cover the vast majority of risk, and they’re available to any ECEC service regardless of size or in-house finance expertise.
Want to go deeper?
We recently ran a webinar on fraud protection for ECEC services. The recording walks through each of these areas in more detail, with worked examples and audience discussion that didn’t make it into this article.
Watch the webinar recording → Most of the fraud that hits early childhood education and care services is preventable. The controls that prevent it are ordinary and inexpensive, and they don’t require finance expertise to put in place.
The reason these controls are so often missing has less to do with anyone’s competence than with the structure of the sector itself.
Why ECEC services sit in a particular danger zone
Fraud risk grows with the distance between the person handling money and the person who genuinely cares about how it’s spent.
In a small owner-operated organisation, those are often the same person. The owner sees everything. As soon as you grow beyond that point, the gap opens up.
Most ECEC operators sit squarely in that gap. Single-centre not-for-profits with volunteer boards. For-profit operators running two to ten centres. Too big for one person to oversee every transaction, but too small to have formal financial controls in place.
Add the specifics of the sector, including volunteer treasurers, short tenures and boards reviewing by exception rather than scrutiny, and you have an environment where fraud is easier than it should be.
The 7 most common fraud types
Most of the fraud risk in the sector falls into seven categories:
- Access and identity fraud. A compromised email or system login used to approve transactions without the account holder’s knowledge.
- Payroll fraud. Unauthorised payroll changes such as inflated hours, fictitious employees, or pay rises that no-one approved.
- Payment redirection. Bank account details changed on legitimate invoices, so payments flow to the fraudster instead of the supplier.
- Fictitious invoices. Invoices from suppliers that don’t exist, approved through a weak process.
- Expense and card fraud. Personal purchases coded as business expenses, often kept small to avoid scrutiny.
- Cash theft. Money collected at fundraising events going missing before it’s counted and recorded.
- Subsidy misrepresentation. Attendance or enrolment data manipulated to inflate CCS claims or misrepresent grant acquittals.
AI has made several of these harder to detect. The phishing email full of typos is a thing of the past. So is the “obviously fake” invoice. Voice cloning means a familiar voice asking for an urgent payment can no longer be taken fully at face value.
The good news: the controls that work against traditional fraud also work against the AI-enhanced version.
The 7 fraud protection shields
These are simple controls that, in combination, prevent the vast majority of fraud.
1. Review the accounts regularly
Almost all fraud flows through a bank account. If your accounts reconcile properly each month, every transaction is recorded, and unusual entries become visible. Regular review is also one of the strongest deterrents available.
2. Use two-factor authentication on everything
Email is the most critical system to protect. A compromised email becomes a master key. It can be used to reset passwords across banking, accounting, payroll and cloud storage.
3. Approvers must see what they approve
A treasurer being asked to approve “$2,400 to XYZ Pty Ltd” without seeing the actual invoice cannot approve it safely. Modern tools like Xero, ApprovalMax and Dext make it easy for the source document to travel with the payment at every stage.
4. Control bank account details tightly
Two layers of protection here. First, limit who has system permission to change supplier and employee bank details. Second, treat any emailed request to change a bank account as a verification trigger. Call back using a number you already have on file, not the one in the email.
5. Separate recording from approving
The person entering and uploading bills should not be the person approving them at the bank. This is the single most fundamental fraud control, and the one auditors look for first.
6. Get the right insurance
Fraud risk insurance isn’t expensive. The catch sits in the fine print. Standard cyber crime cover often excludes social engineering, including the invoice redirection fraud that’s currently the most common attack on ECEC services. Coverage limits are often too low for the size of the organisation. And insurers typically only pay out if you’ve already got 2FA and out-of-band verification in place.
7. Manage cash at events properly
Cash is the hardest transaction type to recover if it goes missing. Eliminate it where you can, using EFTPOS or online payment platforms. Where cash is unavoidable, like fetes, sausage sizzles and raffles, apply the two-person rule at the count and sign-off.
If you ever do suspect fraud
Three things matter from the moment you suspect something is wrong.
Don’t confront the person immediately. It feels like the right thing to do but it almost never is. There is a lot to think through first.
Preserve the evidence before you cut access. Get copies of documents and emails into somewhere they can’t be deleted. Cutting off system access is a clear signal to the person that they’re under investigation, so do the documentation work first.
Get an accountant and a lawyer involved early. They bring different lenses. The accountant helps you trace what happened and stop further loss. The lawyer guides you through your obligations as an employer, which matter a great deal if the suspect is on staff. And contact your insurer immediately, because mishandling the early stages can give them grounds to fight a claim later.
The honest takeaway
You can’t protect against every sophisticated fraud. But the ordinary controls in this article cover the vast majority of risk, and they’re available to any ECEC service regardless of size or in-house finance expertise.
Want to go deeper?
We recently ran a webinar on fraud protection for ECEC services. The recording walks through each of these areas in more detail, with worked examples and audience discussion that didn’t make it into this article.
Watch the webinar recording →
If you’d like to talk through where your service sits on any of these shields, we’re happy to have a conversation.


