Some corporate scandals fade into history. Others continue to shape the way organisations think about governance, accountability and risk.
The Coles Myer procurement fraud falls firmly into the second category.
More than 30 years after former CEO Brian Quinn orchestrated one of Australia's most notorious corporate frauds, the case still offers valuable insights into how procurement fraud occurs and, more importantly, why it so often goes undetected. While technology has transformed finance and procurement functions, the behavioural and organisational weaknesses that enabled the fraud remain surprisingly familiar.
In a recent webinar, fraud and risk specialist Tom McLeod revisited the case, not to examine the legal history but to explore what today's organisations can learn from it. His central message was simple. Fraud rarely succeeds because controls are missing. More often, it succeeds because everyday processes are trusted without enough verification.
Fraud Doesn't Always Look Suspicious
One of the enduring lessons from the Coles Myer case is that fraud often hides in plain sight.
Rather than exploiting complex financial instruments or sophisticated cyber techniques, the scheme relied on something far more ordinary. Maintenance expenditure. Contractor invoices appeared legitimate, the descriptions seemed routine, and the costs blended into a large operational budget. On paper, everything looked reasonable. The problem was that the underlying work was not being performed for the business.
It's an important reminder that routine expenditure deserves just as much attention as high profile capital projects. Categories such as maintenance, facilities management, contractor services and recurring operational expenses generate significant transaction volumes. When teams become accustomed to processing similar invoices every day, unusual activity can be overlooked simply because it appears familiar.
As McLeod observed, organisations should spend more time examining their ordinary spending because that is often where extraordinary misuse is easiest to conceal.
Documentation Isn't the Same as Evidence
Many organisations take comfort in knowing a payment has been approved through the appropriate workflow.
But approval alone doesn't necessarily demonstrate legitimacy.
One of the webinar's strongest messages was the distinction between administrative approval and genuine assurance. An invoice may contain the required signatures, purchase order and payment authorisation, yet still fail to demonstrate that the work was actually completed, the supplier delivered what was promised or the expenditure served a legitimate business purpose.
Strong procurement controls require more than compliance with process. They require evidence that connects every payment to a genuine business outcome.
This is particularly important for contractor payments, consulting engagements and maintenance activities, where supporting documentation can sometimes be broad, generic or difficult to independently verify.
Culture Matters as Much as Controls
Perhaps the most thought provoking part of the discussion focused on organisational culture.
Every organisation has documented policies, delegated authorities and approval workflows. However, those controls operate within human relationships.
When senior executives become involved, many employees become reluctant to ask questions. Staff may assume approvals have already been appropriately considered or worry that raising concerns could be interpreted as challenging authority.
McLeod argued that organisations should reverse this mindset. Expenditure involving senior leaders should attract stronger evidence requirements, not because leaders are less trustworthy, but because robust governance protects everyone involved. Safe escalation pathways for procurement, finance and accounts payable teams are essential if concerns are to be raised without fear of repercussions.
Creating an environment where respectful challenge is expected rather than exceptional remains one of the strongest safeguards against fraud.
Tomorrow's Fraud Won't Look Like Yesterday's
It's tempting to believe that a fraud similar to the Coles Myer case could never happen again.
In reality, the mechanics may change while the underlying behaviours remain the same.
Instead of maintenance invoices, today's equivalent might appear within technology projects, consulting engagements, marketing campaigns or emergency procurement requests. Fraud adapts to whatever an organisation considers routine. If a spending category receives little scrutiny because "that's how we've always done it", it may become the next opportunity for misuse.
Rather than building controls around individual historical cases, organisations should focus on identifying recurring patterns. These include vague descriptions, fragmented evidence, repeated exceptions, unusual supplier behaviour and unexplained changes to vendor information.
These warning signs often emerge long before a fraud becomes visible.
Why Real Time Monitoring Has Become Essential
One advantage organisations now have over those of the early 1990s is access to vastly better data.
Continuous monitoring, advanced analytics and artificial intelligence make it possible to review entire populations of transactions instead of relying on periodic samples.
McLeod believes this represents a significant opportunity for organisations to strengthen fraud prevention. Rather than discovering irregularities months after payments have been processed, businesses can identify unusual supplier activity, approval patterns, vendor master changes and payment anomalies before funds leave the organisation.
During the webinar, he suggested that AI should increasingly be used to identify weak signals across multiple data sets, helping organisations detect patterns that would otherwise remain hidden during manual reviews.
Looking Forward
The Coles Myer fraud is often remembered as a corporate scandal. It should also be remembered as a governance lesson.
Organisations don't need more paperwork. They need better evidence. They don't necessarily need more controls. They need controls that remain effective regardless of who initiates the transaction. Most importantly, they need a culture where asking questions is viewed as good governance rather than unnecessary bureaucracy.
As procurement becomes more digital and business models become increasingly complex, these principles are becoming more important, not less.
Thirty years on, the names and technologies may have changed, but the fundamental challenge remains the same. Every payment should be supported by clear evidence before it leaves the organisation.
That is a lesson every organisation can still learn from today.of the most important lessons organisations can learn.