Risk Assessment, Mitigation and Internal Controls
Eliminating Phone-Line Scam Fraud and Cutting Call Volume by 30%
In 2023, the country office faced a serious reputational threat when clients reported scam calls appearing to come from the official organisational phone line. As Integrity Officer, I traced the vulnerability to unrestricted staff access across more than 400 desk lines and 52 duty phones, with no SOPs governing after-hours calls. I led the technical and policy response that closed the vulnerability, retrieved 45 mobile phones, and reduced overall call volume by 30%. Since January 2024, the organisation has received zero complaints against its official number.
- Reduction in call volume
- 0%
- Mobile phones retrieved
- 0
- Complaints since Jan 2024
- 0
Reduction in call volume
Mobile phones retrieved
Complaints since Jan 2024
The Context
The organisation's public commitment that all services are free of charge made phone-based scam allegations an acute reputational risk. More than 400 staff could dial out directly from desk phones with no individual accountability, and 52 field staff held duty phones with discretionary use.
The Challenge
A review of monthly calls dialled reports identified more than 200 calls placed to clients between 1800 and 0200, well outside working hours of 0800 to 1500. No SOPs, emergency guidance or line-manager approvals existed to explain these calls, and senior management had no visibility into the pattern.
The Strategic Approach
How It Was Solved
Assessment phase
met with the Head of IT to assess the feasibility of PIN-based accountability, the cost of implementation and the risk of landline cloning targeting the organisation as a high-profile client.
Implementation phase
coordinated with the telecoms provider to run a systems upgrade, then rolled out individual PINs to all staff so every call could be traced to a specific user.
Consolidation phase
reviewed duty phone holdings with line managers, drafted a Mobile Services SOP and an Anti-fraud SOP annex on Calls Dialled Reports, and worked with the Communications Team to publicise the single verified contact number.
Measurable Results
- Overall call volume dropped by 30% against historical calls dialled reports.
- 45 mobile phones were retrieved countrywide, with only 7 duty phones retained under line-manager custody.
- More than 50 scam calls impersonating the organisation have since been identified and reported to the authorities.
- Zero complaints against the official phone number have been recorded since January 2024.
Broader Impact
- Restored client trust in the organisation's official communication channel.
- Introduced individual accountability to a system that previously had none.
- Enabled a full migration from hardware desk phones to soft phones with VPN-based continuity.
- Strengthened the relationship between the Integrity function and the Communications team.
A reputational crisis is often a control gap in disguise. Fixing the underlying access control mattered more than responding to individual complaints.
This case demonstrates how integrity oversight, IT collaboration and policy development can convert a live reputational threat into a stronger, more accountable system. The result was not just a technical fix but a lasting shift in how the organisation manages telecommunications risk.
Tools Used in This Case
Microsoft Office Excel
used to compile and analyse monthly calls dialled reports and correlate them against client complaint data, drawing on telecom provider reports downloaded and reviewed against client contact details in proGres.
SharePoint
used to host and disseminate the drafted Mobile Services and Anti-fraud SOP annex.
Power BI
used to visualise call volume trends before and after PIN rollout for senior leadership briefings.
Competencies Evidenced
Discuss This Type of Engagement
Reach out to talk through a similar investigation, safeguarding rollout or compliance engagement.