Why is fraud risk overlooked in transformation programmes? Farhan Khan, Senior Director and Head of Forensics at BDO Saudi Arabia, shares insights on the fraud risks facing large transformation programmes in Saudi Arabia and explains how organisations can strengthen governance, enhance oversight and protect long-term value.
Saudi Arabia’s transformation agenda under fraud prevention Vision 2030 projects continues to drive unprecedented levels of investment across infrastructure, technology, digitisation, governance reform and operational modernisation. Across both the public and private sectors, organisations are undertaking complex transformation programmes designed to improve efficiency, accelerate growth, strengthen competitiveness and modernise operating models.
The same complexity that enables transformation can also create hidden opportunities for fraud, misconduct and control failure. Large transformation initiatives often operate in fast-moving, multi-layered environments involving multiple stakeholders, external vendors, evolving scopes, significant budgets and compressed timelines. In such conditions, traditional control environments can become strained, fragmented, or temporarily bypassed in favour of speed and execution.
This risk is particularly relevant in Saudi Arabia and the wider GCC, where organisations are simultaneously managing rapid digital transformation fraud risk, large-scale infrastructure investment, evolving regulatory expectations and accelerated execution timelines. As organisations focus on delivery, innovation and compliance, hidden fraud risks can remain undetected until financial, operational, or reputational damage has already occurred.
Where do hidden fraud risks typically arise?
Transformation programmes often create temporary operating environments that differ significantly from normal business operations. Governance structures evolve rapidly, third-party dependencies increase and decision-making becomes decentralised across project teams, consultants, contractors and programme management offices.
Some of the most common fraud exposure areas include:
- Procurement and vendor onboarding under accelerated timelines
- Contract amendments concealing inflated billing or unsupported claims
- Weak segregation of duties within programme teams
- Excessive system access rights during digital transformation
- Inadequate oversight over third-party contractors and implementation partners
- Pressure to demonstrate progress, resulting in temporary control overrides
Procurement fraud in the KSA is one of the most significant risks associated with procurement and change management activities in large transformation programmes. Large programmes frequently involve repeated contract variations, evolving deliverables and substantial financial approvals. Without strong governance and transparent review mechanisms, these changes can create opportunities for manipulation, duplicate payments, or favouritism.
What causes fraud in ERP and digital transformation projects?
Digital transformation initiatives create additional exposure as organisations implement enterprise systems, automate workflows and migrate data. Internal controls may unintentionally weaken during transition periods. Privileged users may retain excessive access, monitoring processes may lag behind deployment and system controls may not be fully tested before go-live.
Common types of fraud and misconduct: signs of fraud in large projects
Misconduct in transformation programmes is often more sophisticated than traditional transactional fraud and, as a result, considerably harder to detect. It tends to emerge gradually, concealed within the complexity of multi-vendor delivery environments and compressed approval cycles.
Typical examples include:
- Procurement manipulation and bid rigging
- Inflated invoices and duplicate payments
- Undisclosed conflicts of interest involving vendors or consultants
- Misuse of project budgets or unsupported change requests
- Cyber-enabled fraud linked to weak access governance
- Manipulation of programme reporting to conceal delays or cost overruns
Farhan Khan, Senior Director and Head of Forensics at BDO Saudi Arabia, says, “In many cases, early warning signs are behavioural rather than financial — including resistance to oversight, excessive urgency around approvals, reluctance to share information, or repeated bypassing of established controls.”
In some cases, misconduct may initially arise from operational pressure to demonstrate progress rather than deliberate fraudulent intent. However, undocumented workarounds and repeated control overrides can gradually evolve into larger governance failures that are far more difficult to unwind.
Why do organisations overlook fraud risks in transformation programmes?
Transformation programmes are typically measured against timelines, implementation targets and budget performance. Leadership attention naturally focuses on delivery outcomes and operational continuity, which means fraud indicators often become hidden within broader programme complexity.
A further challenge is the assumption that existing enterprise controls automatically extend into transformation environments. In practice, transformation programmes frequently operate through parallel governance structures with temporary teams, evolving responsibilities and accelerated approval processes that fall outside the reach of standard oversight mechanisms.
The involvement of major technology vendors or global implementation partners can also create a false sense of assurance. Organisations may assume that sophisticated delivery environments inherently reduce misconduct risk, when in fact complexity itself frequently reduces visibility and accountability.
How can organisations strengthen fraud resilience in the KSA?
Organisations can significantly reduce exposure by embedding forensic risk management and fraud detection into programme governance from the outset, rather than treating it as a reactive exercise reserved for when something has already gone wrong. Fraud risk management should evolve alongside programme delivery, rather than operate as a separate compliance exercise.
Key measures include:
- Conducting fraud risk assessments at critical stages of programme execution
- Implementing continuous monitoring and data analytics across high-risk transactions
- Strengthening governance over procurement, change orders and vendor approvals
- Establishing clear ownership for fraud risk, investigation protocols and escalation routes within programme governance
- Establishing independent oversight for large transformation initiatives
- Embedding cybersecurity and access governance controls into digital programmes
- Encouraging whistleblowing and independent reporting mechanisms
- Integrating forensic, risk, cybersecurity and internal audit specialists into programme oversight
Advanced analytics are becoming increasingly important in fraud detection for large-project environments. Data-driven monitoring can identify unusual vendor behaviour, duplicate payments, pricing anomalies, suspicious access activity and patterns inconsistent with expected project delivery, often well before issues escalate.
Digital transformation fraud risk: a practical scenario
Consider a large public sector digital transformation programme launched under Vision 2030. Vision 2030 governance risk becomes a key challenge as organisations implement ERP systems, migrate data, integrate cybersecurity and deliver citizen-facing platforms. To meet nationally visible delivery milestones, the organisation appoints a principal systems integrator supported by multiple technology subcontractors under accelerated procurement and compressed governance timelines.
A subsequent forensic review identifies significant hidden control failures. A subcontractor linked to a senior programme official receives recurring payments for software licences and digital services that were never independently verified or fully activated. Change requests and contract variations are repeatedly approved by the same individual without effective challenge, quietly expanding project scope and fee structures. At the same time, substantial consultancy charges from an offshore advisory provider continue to be processed despite limited evidence of deliverables.
Because programme reporting remained heavily focused on implementation milestones, budget utilisation and regulatory readiness, financial irregularities accumulated unnoticed across multiple workstreams for more than eighteen months.
The review ultimately reveals fragmented oversight, weak segregation of duties, inadequate subcontractor governance and limited visibility across delivery layers. By strengthening governance, introducing continuous monitoring and deploying targeted forensic analytics, leadership is able to contain financial exposure, improve accountability and restore stakeholder confidence.
The importance of early intervention in the KSA
Large transformation programmes represent strategic investments that shape the future direction of organisations. However, the same complexity that enables transformation can also conceal significant fraud exposure if governance and oversight fail to evolve at the same pace.
Organisations that proactively address forensic risk challenges through stronger controls, continuous monitoring, forensic readiness and independent oversight are better positioned to protect enterprise value, maintain stakeholder trust and achieve successful transformation outcomes.
“In increasingly complex environments, effective fraud risk management is no longer simply a compliance exercise. It is a critical component of sustainable transformation, operational resilience and confident decision-making. Organisations that fail to strengthen oversight at the same pace as execution may ultimately place the programme’s success at risk.” Farhan Khan mentions.

