ANTI FRAUD POLICY
Introduction: The Anti-Fraud Policy of Star Health & Allied Insurance Co. Ltd. (hereinafter referred to as "SHAIC") outlines the framework for preventing, detecting, investigating, and reporting fraud in compliance with IRDAI guidelines. This policy establishes a comprehensive approach to deter, prevent, detect, report, and remedy fraud risks across all operations of the organization.
1.1 Objective
Effective deployment of controls which will aid in the identification, detection, prevention and investigation of reported frauds. SHAIC is dedicated to conducting business in a fair and honest manner and will work to eliminate fraud from all activities. SHAIC has a "Zero-Tolerance" stance against fraud and will not tolerate any dishonest or fraudulent behaviour on the part of internal or external stakeholders.
1.2 Applicability / Scope
This policy applies to any fraud or suspected fraud involving employees as well as shareholders, consultants, vendors, contractors, outside agencies doing business with SHAIC and/or any other parties having a business relationship with SHAIC including insurance advisors/ brokers/ corporate agents of SHAIC. The policy would also be applicable to policyholders and beneficiaries. Any investigation activity required will be conducted irrespective of the suspected wrongdoer’s length of service, position/title, or relationship to SHAIC.
Fraud includes any act, omission, concealment of any fact, or abuse of position committed by any person or any other person with the connivance of any person, in any manner, with intent to deceive, to gain undue advantage from, or to injure the interests of the company or its shareholders or its creditors or any other person.
Fraud in Health Insurance falls into various categories depending upon the person committing such activities mentioned hereunder:
3.1 Internal Fraud
Fraud / misappropriation against SHAIC by its Directors, Managers and/or any other officers or staff members (by whatever name called). Some of the examples include but are not limited to the following.
- Misappropriating funds
- Fraudulent financial reporting
- Inflating expense claims/overbilling
- Forging signatures
- Removing money from customer accounts
- Falsifying documents
- Intentional concealment
3.2 Policyholder Fraud
Fraud against SHAIC in the purchase and/or execution of an insurance product, including fraud at the time of making a claim. Some of the examples include but are not limited to the following.
- Fabrication of bills/documents
- Fraudulent death claim
- Non-disclosure of Pre-Existing Disease (PED) illness
- Suppression of facts
- Staging the occurrence of incidents
3.3 Distribution Channel Fraud
Fraud by Insurance Agents, Brokers, POSP, IMF, Corporate Agents. Some of the examples include but are not limited to the following.
- Premium diversion - intermediary takes the premium from the purchaser and does not pass it to SHAIC.
- Inflates the premium, passing on the correct amount to SHAIC and keeping the difference.
- Non-disclosure or misrepresentation of the risk to reduce premiums.
- Commission fraud - ensuring non-existent policyholders while paying a first premium to SHAIC, collecting commission and annulling the insurance by ceasing further premium payments.
- Document tampering, falsification of records and policy churning by the intermediaries to their advantage.
3.4 External Fraud
Fraudulent acts committed by individuals or entities outside SHAIC, such as vendors, hospitals, diagnostic centres, service providers, and other third parties. Some examples include, but are not limited to, the following:
Vendor/Service Provider Fraud
- Submission of inflated or false invoices for services not rendered or partially rendered.
- Collusion with internal employees to approve fraudulent payments.
- Misrepresentation of credentials or capabilities during empanelment or contract execution.
Hospital/Healthcare Provider Fraud
- Overbilling for medical procedures or diagnostic tests.
- Charging for non-performed treatments or unnecessary procedures.
- Collusion with policyholders or intermediaries to generate fraudulent claims.
3.5 Affinity/Complex Fraud
Fraud involving collusion among multiple parties, often sophisticated in nature, aimed at causing financial or reputational harm to SHAIC. Some examples include, but are not limited to, the following:
Organized Crime Rings
- Coordinated fraudulent claims targeting insurance products.
Document-Based Fraud
- Use of forged or fabricated documents across multiple touchpoints to perpetrate fraud.
Technology-Enabled Collusion
- Unauthorized access to SHAIC systems by external parties to manipulate data or transactions.
3.6 Cyber or New Age / Online Frauds
Cyber / Online frauds refer to various kinds of frauds committed through the Internet, including phishing emails to gather personal data, hacking of servers/computer systems, theft of data, passwords, cloning, etc. Some examples include, but are not limited to, the following:
Cyber / Online frauds can lead to:
- Loss of confidential data
- Sensitive information being compromised
- Disruption of operations
- Loss of trust
- SHAIC shall be constantly vigilant in deterring fraudsters. As part of its corporate governance, the Board of SHAIC shall recognise and understand the risks of fraud to its organisation, including the potential types and impact of fraud. By understanding the risks of internal, external, policyholder, claims and distribution channel fraud, SHAIC shall decide which procedures and controls can be implemented effectively and efficiently to manage these risks.
- SHAIC shall address fraud risk when establishing its mission, strategy and business objectives. The overall policy shall be consistently implemented in departmental objectives. It shall be reflected in the relevant operational procedures and controls.
- For this purpose, SHAIC shall:
- establish and maintain a sound control environment through policies, procedures and controls.
- demonstrate proper support by the Board and Senior Management (“tone at the top”), and overall communication of these values throughout its entire organisation.
- organise and collect management information with respect to fraud in insurance, making it available in a timely manner for the Board and Senior Management to monitor developments and take appropriate action. This information shall be used to periodically evaluate the effectiveness of policies, procedures and controls and make changes where necessary.
- As part of its fraud risk management, SHAIC shall have a set of measures and procedures to identify Red Flag Indicators (RFIs) to be able to respond adequately and quickly to (suspected) cases of fraud. These measures and procedures would include possible fraud investigations.
5.1 Board of Directors
The Board of Directors provides the overall guidance on fraud management and has delegated the responsibilities relating to fraud management activities to the Board Risk Management Committee (BRMC).
- Board Risk Management Committee (BRMC)
The Board Risk Management Committee (BRMC) is responsible for effective implementation and oversight of the fraud risk management framework.
- Fraud Monitoring Committee (FMC)
Fraud Monitoring Committee is constituted with senior-level officers headed by the Chief Risk Officer (CRO).
FMC is responsible for:
- Review and monitoring of the Anti-Fraud policy.
- Operationalizing the fraud risk management framework and overseeing activities, as appropriate, to ensure fraud deterrence, prevention, detection, reporting and remediation.
- Designing procedures for detecting, reporting, investigating and taking proper action against the persons committing fraud.
- Furnishing reports on frauds to the Authority, as required and the annual submission of the Fraud Monitoring Report (FMR) at the end of each financial year.
- Maintaining an incident database of persons convicted of or attempting fraud.
5.4 Fraud Monitoring Unit (Vigilance)
Fraud Monitoring Unit (Vigilance) will be responsible for laying down appropriate fraud management processes and procedures in consultation with the CRO, across the company and shall ensure effective implementation of the measures suggested by FMC.
Functions of Fraud Monitoring Unit (Vigilance) shall include, but not be limited to the following:
- Fraud Monitoring Unit (Vigilance) will proactively identify potential areas of fraud. It shall undertake data analytics to find any fraud patterns/trends and subject the same to field/vigilance investigation.
- Fraud Monitoring Unit (Vigilance) shall collate all cases of fraud reported by the whistle-blower or any other entity.
- Fraud Monitoring Unit (Vigilance) shall investigate all such cases and render a report duly highlighting the breaches of conduct, processes and systems, etc. Report shall also highlight the financial implication, if any. ·
Disciplinary Action Process: For all proven cases, disciplinary action shall be initiated as per the defined disciplinary matrix and shall be shared with FMC for information.
Fraud Monitoring Unit (Vigilance) & Internal Audit Department operating in the organizational setup will have the primary responsibility to identify, detect, and report insurance frauds. SHAIC will have well-defined procedures to identify, detect, investigate and report frauds. The Risk Management, Fraud Monitoring Department and Information Technology will develop/ manage systems and frameworks and analytical tool methodologies to identify potential fraud areas/red flags.
In accordance with the IRDAI guidelines and industry best practices, SHAIC shall actively participate in the Insurance Information Bureau of India (IIB) Fraud Monitoring Framework to strengthen fraud prevention and detection measures.
All persons, including employees, vendors, agents, and intermediaries, are expected to take all reasonable steps to prevent the occurrence of frauds, including online frauds, and to identify and report instances of known or suspicious fraud at “whistleblower@starhealth.in”. Complaints/disclosures shall be dealt with in accordance with the Whistle-blower Policy.
Whenever an allegation of fraud of grave nature is prima facie found to be true, efforts will be taken to file a complaint with police authorities for initiating action under the criminal law of the land. The Vigilance and Legal departments will help in drafting the complaints and liaising with the Police.
Regular training will be imparted with the aim of raising awareness of the fraud risk and the importance of compliance with internal control procedures and ways of preventing fraud.
SHAIC shall inform both potential clients and existing clients about their fraud prevention policies. SHAIC shall take steps to appropriately include necessary caution in the insurance contracts / relevant documents, duly highlighting the consequences of submitting a false statement and / or incomplete statement, for the benefit of the policyholders, claimants, and beneficiaries.
SHAIC shall furnish the statistics on various fraudulent cases which come to light and action taken thereon shall be filed with the Authority in Form FMR-1, providing details of
- Outstanding fraud cases; and
- Closed fraud cases
within 30 days of the close of every financial year.
The policy shall be reviewed annually by the Chief Risk Officer and approved by the Board. The policy may also be modified based on the newly released changes to acts, regulatory guidelines, independent audits and/or internal review.