Fraudulent quality assurance and safety non‑compliance
Testing, quality assurance, and safety controls are compromised through falsified results, substitution of materials, or bribery or conflicts-of-interest involving inspectors, increasing the risk of failures and accidents.
Red Flags & Indicators
- Test certifications and reports lack end-to-end traceability (sample IDs, custody records, timestamps) or show suspiciously consistent results.
- Materials delivered or installed diverge from approved specifications without justification, or substitutions are made without documented approval.
- Safety incidents and near-misses are not reported or underreported, and corrective actions repeatedly exceed past due dates.
- Inspector/lab independence is questionable (repeat engagements, undeclared conflicts, templated and identical sign-offs).
- Non-conformities are closed without verifiable evidence, and the same defects recur across inspections.
Stakeholder Guidance
Stakeholder Exposure
Exposure includes increased risk of substandard materials, falsified tests and operational failure; costly rework and stop-work events; higher accident and liability risk; warranty and insurance impacts; and higher reputational risk.
Decision Point
During testing, proceed only with traceable quality assurance systems, approved materials, and established health and safety standards.
Mitigation Actions
• Maintain complete quality assurance, quality control, and health, safety and environment (HSE) records (sample IDs, chain-of-custody, test results, inspection logs, non-conformance reports)
• Use digital tools that auto timestamp entries to avoid falsification or backdating of quality and safety documentation
• Maintain a full audit trail of quality and safety documentation (who created, edited, when, and what changed in each document version)
• Verify materials against approved specifications (receiving inspection report, batch and heat numbers, traceability)
• Adopt a system to red flag unapproved materials substitutions
• Quarantine non-conforming materials and document what is done with those materials
• Separate quality verification from production, payment, and certification roles
• Use independent or second-line checks for critical tests and retain evidence for audits
• Use internal compliance escalation processes and whistleblower channels, where available, to report pressure to bypass tests, close non-conformance reports without evidence, or underreport incidents
• Stop work when critical controls fail until corrective actions are verified
Mitigation Resources
Assess fraud risks and apply prevention, detection, investigation, and corrective-action controls to quality and safety records, including test results, inspection records, non-conformance reports, material traceability records, and corrective actions.
Fraud control management — https://toolbox.infrastructuretransparency.org/resource/fraud-control-management/Control quality and safety records, including test results, inspection records, non-conformance reports, material traceability records, and corrective actions, through formal evidence requirements, independent review, and verification before internal sign-off, certification requests, or payment claims.
Change control, delivery verification, and payment integrity — https://toolbox.infrastructuretransparency.org/resource/change-control-delivery-verification-and-payment-integrity/Failure Cases
Good Practices
Stakeholder Exposure
Exposure includes catastrophic failure and downtime risk; ESG and safety risk; reputational harm; costly remediation and delays; insurance and liability events; and decrease of project value.
Decision Point
At drawdown milestones, disburse only where quality assurance and safety evidence is independently verified; hold payments pending re-testing and implementation of corrective actions.
Mitigation Actions
• Include audit/verification rights over quality assurance and quality control records and labs/inspectors used
• Treat repeated anomalies (uniform results, missing traceability, repeat sign-offs, closed non-conformance reports without evidence) as a suspension trigger
• Commission third-party re-testing or site verification after repeated anomalies
• Require disclosure of timely incident and near-miss reporting and corrective-action tracking (owners, deadlines, verification of closure)
• Pause disbursements in case of lack of disclosure on incident reporting and corrective actions, or where corrective actions are overdue or being bypassed
Mitigation Resources
Require, through financing conditions, formal evidence and independent verification for quality and safety records, including test results, inspection records, non-conformance reports, and corrective actions, before disbursement decisions.
Change control, delivery verification, and payment integrity — https://toolbox.infrastructuretransparency.org/resource/change-control-delivery-verification-and-payment-integrity/Use an independent technical adviser to verify test results, traceability, inspection records, non-conformance reports, and corrective-action evidence, and to challenge weak or inconsistent support in quality and safety records.
Independent technical due diligence and monitoring — https://toolbox.infrastructuretransparency.org/resource/independent-technical-due-diligence-and-monitoring/Failure Cases
Good Practices
Stakeholder Exposure
Exposure includes higher risk of unsafe assets and service disruptions; higher lifecycle costs from defects; legal liability and investigations after incidents; increased risk of rework and delays; and loss of public trust.
Decision Point
Before accepting critical works and material, require evidence that quality assurance and safety tests are complete and traceable; otherwise, order re-testing and corrective actions.
Mitigation Actions
• Conduct random surprise audits and risk-based spot checks
• Maintain a complete auditable record for inspection and certification
• Separate contractor and supervision from inspection and certification roles
• Document access to quality assurance records
• Require conflict-of-interest declarations for labs and inspectors
• Rotate and independently verify critical tests where feasible
• Commission re-testing in case of critical inconsistencies (missing traceability, repeat uniform results, unapproved substitutions, or closed non-conformance reports without evidence)
• Quarantine critical materials, and withhold acceptance and payment until verification against approved specifications
• Refer credible falsification and bribery concerns to independent oversight bodies, suspending approvals pending review, and documenting corrective actions
• Publish material quality failures and corrective actions
Mitigation Resources
Require complete quality and safety records, including traceable test results, inspection records, non-conformance reports, corrective-action evidence, and material traceability records, and verify them before certification, acceptance, or payment.
Change control, delivery verification, and payment integrity — https://toolbox.infrastructuretransparency.org/resource/change-control-delivery-verification-and-payment-integrity/Assess fraud risks and apply prevention, detection, investigation, and corrective-action controls to quality and safety records, including falsified test results, closed non-conformance reports without evidence, unapproved substitutions, and missing traceability.
Fraud control management — https://toolbox.infrastructuretransparency.org/resource/fraud-control-management/Publish and maintain public access to key quality and safety records, including material quality failures, major non-conformance findings, and corrective actions, with only lawful redactions.
Transparency and data disclosure standards — https://toolbox.infrastructuretransparency.org/resource/transparency-and-data-disclosure-standards/Failure Cases
Good Practices
Stakeholder Exposure
Exposure includes higher risk to community safety and environmental harm; limited transparency on testing and incidents; higher grievance burden; retaliation risk for whistleblowers; and reduced accountability for corrective actions.
Decision Point
During project execution, submit access to information to request test certification and inspection reports. Decide whether to (a) escalate through oversight channels to report credible signs of serious issues and lack of transparency, or (b) monitor while safely gathering evidence.
Mitigation Actions
• Mobilise communities to identify issues related to visible work quality and safety outcomes (defects recurring, unsafe practices, incident patterns)
• Engage oversight bodies when serious or repeated issues are identified (use safe, confidential reporting and anonymisation where the risk of retaliation is significant)
• Advocate for disclosure of project information based on recognised infrastructure data standards such as the OC4IDS
Mitigation Resources
Use independent monitoring or social accountability to compare disclosed quality and safety records with visible site conditions, recurring defects, incident patterns, and corrective action in practice; document unexplained gaps, track follow-up actions, and raise them through oversight channels.
Independent monitoring, assurance, and social accountability — https://toolbox.infrastructuretransparency.org/resource/independent-monitoring-assurance-and-social-accountability/Submit protected complaints or reports through complaints, ombud, audit, or other oversight channels where falsified test results, substituted materials, unsafe practices, or suppressed non-conformance findings are identified; document evidence and timelines, and support safe reporting where retaliation risk is material.
Grievance, complaints, and protected reporting — https://toolbox.infrastructuretransparency.org/resource/grievance-complaints-and-protected-reporting/Review publicly disclosed quality and safety records, including inspection findings, non-conformance reports, corrective-action status, and published reasons for major quality failures or safety incidents; identify disclosure gaps, missing justifications, or unexplained decisions, and raise concerns about non-disclosure with an oversight body.
Transparency and data disclosure standards — https://toolbox.infrastructuretransparency.org/resource/transparency-and-data-disclosure-standards/