Back to Compliance

Fraud Prevention and Staff Accountability

CareLedgerPro

Version 1.0 — Last updated: 6 August 2026

Money held on behalf of adults who receive care is one of the most common routes to financial abuse in the sector. This statement sets out the controls the platform provides, what they do and do not achieve, and where responsibility sits between CareLedgerPro and the provider.

1. Purpose and scope

The policy applies to all recording of service-user money and care-unit petty cash within CareLedgerPro, and to all accounts on a provider's tenancy regardless of role. It supports the provider's own financial-abuse and safeguarding policies; it does not replace them.

Relevant to Care Act 2014 safeguarding duties, the Mental Capacity Act 2005 where a service user does not manage their own money, CQC quality statements on safeguarding and governance, and the Fraud Act 2006.

2. Preventive and detective controls

Attribution of every entry

Each transaction stores the acting staff member's identity and name at the time of entry, the timestamp, the funding source, the category and any notes. There is no anonymous or shared-account route into the ledger; accounts are invite-only and personal.

Receipt evidence thresholds

A receipt is required above a configurable value. Purchases can be captured with the built-in document scanner, and amounts read from the receipt are compared against the amount entered so mismatches surface immediately.

Countersignature on high-value entries

Transactions at or above the configured high-value threshold require a second signature before they are treated as approved. Raising an amount across the threshold through a correction clears the previous approval and forces re-authorisation.

Limited, reasoned corrections

Staff may correct only the amount and receipt amount of their own transaction, within 24 hours, with a written reason of at least ten characters. Managers and administrators may correct at any time. Original values are preserved alongside the corrected ones and a correction count is kept.

Voids instead of deletions

Transactions cannot be deleted. A mistaken entry is voided with a reason, the balance effect is reversed, and both the original and the void remain visible in the history.

Append-only logs

The audit log, user audit log, data-access log and communication edit history are protected by database triggers that block updates and deletions, including by administrators.

Segregation and least privilege

Staff see only the client groups they are assigned to. Role changes, user deactivation and 2FA resets are administrator-only and are recorded in the user audit log with the acting administrator's identity.

Cash float control

Petty-cash balances are held per care unit, spending can be blocked when the float is insufficient, and every movement writes a ledger entry with the resulting balance. Weekly reconciliation records actual counted cash against the expected figure and is signed off.

Spending plans

Optional weekly or monthly limits per service user, overall and by category, with warning at 75 per cent, breach flagging, and a recorded reason where a limit is deliberately exceeded.

Detection reporting

Standing reports cover missing receipts, receipt-to-entry mismatches, flagged transactions, unreconciled units and spending-plan breaches. A daily digest email summarises outstanding items for managers.

3. Staff accountability statement

Everyone with an account is accountable for the entries made under it. In practice:

  • Accounts are personal. Sharing credentials, or recording a transaction under another person's account, is a disciplinary matter for the provider and undermines every control on this page.
  • Two-factor authentication is mandatory for all roles, so an entry attributed to a member of staff was made by someone holding both their password and their enrolled device.
  • Entries are recorded contemporaneously and reflect what actually happened, including the correct funding source.
  • Mistakes are corrected openly through the correction or void routes with an honest reason, not by re-entering data to obscure the original.
  • Every view of a client or transaction record is logged, so browsing records outside an assigned group is visible to administrators.
  • Concerns about another person's handling of service-user money are raised under the provider's safeguarding and whistleblowing procedures, not resolved informally in the ledger.

4. Monitoring and review

Managers are expected to review flagged transactions and missing receipts at least weekly, complete and sign off cash reconciliation for each care unit weekly, and review spending-plan breaches when raised. Administrators review the user audit log — role changes, deactivations, 2FA resets — at least monthly.

The daily digest email lists outstanding receipts, flagged entries, unreconciled units and plan breaches so that review is prompted rather than relying on someone remembering to look.

5. Responding to a suspected case

  1. Preserve the record. Do not void or correct entries under investigation; the history is evidence and is append-only for that reason.
  2. Restrict access. An administrator can deactivate the account or remove group assignments immediately; the change is recorded with the acting administrator's identity.
  3. Export the evidence: the transaction history, receipts, signatures, audit log and data-access log for the affected service user and period.
  4. Escalate under the provider's safeguarding policy — local authority safeguarding, the police where a criminal offence is suspected, and the CQC where notification is required.
  5. If personal data has also been exposed, raise a record in the built-in breach register so the 72-hour ICO assessment clock is tracked.

6. Limits of these controls

These are recording and detection controls, not a guarantee against fraud. The platform cannot verify that a purchase actually took place, that a receipt belongs to the transaction it was attached to, or that cash counted at reconciliation was counted honestly. It cannot detect collusion between staff who countersign for one another, and it does not perform automated behavioural profiling of staff.

What it does is make every entry attributable, make alteration visible rather than silent, and put the discrepancies in front of a manager quickly. Recruitment checks, supervision, rota-level segregation of duties and acting on what the reports show remain the provider's responsibility.

Contact

For help exporting evidence for an investigation, or to discuss these controls with your auditor, contact support@careledgerpro.co.uk.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.