Skip to main content
Category: Anti-Bribery and Corruption

Improper Payments

Also known as: Payment Errors, Payment Integrity Issues
Simply put

An improper payment is a payment that should not have been made or was made in the wrong amount under the rules governing a program or contract. This includes payments to the wrong recipient, in an incorrect amount, or without sufficient documentation to confirm the payment was proper. Importantly, an improper payment is not necessarily the result of fraud; it often reflects errors, missing documentation, or failure to meet program payment requirements.

Formal definition

In the U.S. federal context, an improper payment is generally defined as a payment that was made in an incorrect amount under statutory, contractual, administrative, or other legally applicable requirements, including overpayments and underpayments, payments to ineligible recipients, and payments lacking adequate supporting documentation. Under the framework applied by agencies such as CMS and DOL, improper payments are those that do not meet program payment requirements and should not be conflated with confirmed fraud, which requires proof of intent; improper payments may arise from documentation gaps, eligibility errors, or administrative mistakes, and are distinct from waste, fraud, and abuse even where efforts to reduce all of these overlap. Federal agencies estimate improper payments across their programs and report them in payment integrity reporting; for fiscal year 2025, 15 federal agencies reported a total estimate of approximately $186 billion across 64 programs, an increase of about $24 billion from the prior fiscal year. This entry addresses the U.S. federal usage reflected in the evidence; the concept, its definition, and reporting obligations vary by jurisdiction, sector, and entity type, and this entry is educational and not legal, audit, or compliance advice.

Why it matters

Improper payments represent a significant and persistent challenge to payment integrity in government programs. In the U.S. federal context, the scale is substantial: for fiscal year 2025, 15 federal agencies reported a total estimate of approximately $186 billion in improper payments across 64 programs, an increase of about $24 billion from the prior fiscal year. Numbers of this magnitude draw sustained attention from oversight bodies such as the Government Accountability Office, program regulators, and legislators, and they reflect a control environment where errors, eligibility misjudgments, and documentation gaps can compound across high-volume, high-value programs.

A critical point for governance, risk, and compliance professionals is that an improper payment is not the same as fraud. Fraud requires proof of intent, whereas improper payments frequently arise from administrative mistakes, missing or insufficient supporting documentation, or a failure to meet specific program payment requirements. Agencies such as CMS emphasize that improper payments are simply payments that do not meet program payment requirements, and this distinction matters because it shapes the appropriate response: remediation of a documentation or eligibility control weakness is different from investigation and enforcement of intentional wrongdoing. Conflating the two can misdirect resources and mischaracterize the underlying issue.

For compliance and internal control functions, improper payment estimates serve as a barometer of control design and operating effectiveness in the payment lifecycle. Because improper payments include both overpayments and underpayments, they signal risks in eligibility verification, recipient validation, amount calculation, and recordkeeping, each of which may warrant distinct control improvements. Understanding where an improper payment sits on the spectrum from an isolated documentation lapse to a systemic eligibility failure is essential to prioritizing remediation and to accurate payment integrity reporting.

Who it's relevant to

Chief Compliance Officers and Payment Integrity Teams
Compliance leaders responsible for programs subject to federal payment integrity requirements need to understand how improper payments are defined and reported. Because improper payments frequently stem from documentation gaps or eligibility errors rather than intent, compliance teams should focus on ensuring that payment requirements are met and adequately evidenced, and should be careful not to characterize an improper payment as fraud absent proof of intent.
Internal Auditors and Assurance Functions
Internal audit and other assurance providers assess whether controls over eligibility verification, amount calculation, recipient validation, and supporting documentation are designed appropriately and operating effectively. Improper payment estimates offer a signal of potential control weaknesses across the payment lifecycle, helping auditors prioritize testing and evaluate the reliability of payment integrity reporting.
Program and Financial Management
Managers who own program operations and payment processes are accountable for meeting program payment requirements and for maintaining documentation sufficient to confirm payments are proper. They bear operational responsibility for remediating the underlying error, eligibility, or documentation issues that give rise to improper payments, including both overpayments and underpayments.
Governing Boards and Oversight Bodies
Boards and equivalent oversight bodies exercise oversight of the control environment and risk management, rather than performing day-to-day payment operations. Improper payment estimates and payment integrity reporting can inform their oversight of management's remediation efforts and of the organization's exposure to payment integrity risk, particularly given continued scrutiny from bodies such as the Government Accountability Office.

Inside Improper Payments

Facilitation and Bribery Payments
Payments made to secure an improper business advantage or to influence the acts or decisions of a recipient, including public officials or private counterparties. The treatment of small facilitation payments varies by jurisdiction and applicable anti-bribery regime, and what is permitted under one law may be prohibited under another.
Third-Party and Intermediary Payments
Payments routed through agents, distributors, consultants, or other intermediaries that may be used to disguise the ultimate recipient or purpose. These typically warrant heightened scrutiny because liability can attach to the entity even when the payment is made by a third party acting on its behalf.
Books and Records Component
The requirement, under certain regimes such as the accounting provisions of anti-corruption statutes, to maintain accurate books and records and adequate internal accounting controls. Mischaracterizing or concealing a payment in the financial records can itself give rise to violations, separate from the underlying payment.
Gifts, Hospitality, and Entertainment
Non-cash items of value that may cross into improper territory depending on value, frequency, intent, and the recipient's role. Whether such items are acceptable generally depends on the applicable policy, jurisdiction, and the facts of each situation.
Accountability and Ownership
Compliance typically owns the design and monitoring of anti-corruption controls, management owns their operation within the business (first line), and the board or its audit or risk committee provides oversight. These roles are distinct and should not be conflated.

Common questions

Answers to the questions practitioners most commonly ask about Improper Payments.

Is 'improper payment' just another term for bribery or corruption?
No. While bribery and corruption can constitute improper payments, the term is generally broader. In many contexts an improper payment refers to any disbursement that should not have been made, or that was made in an incorrect amount or to the wrong party, this can include payments arising from error, fraud, insufficient documentation, or failure to follow required procedures, not solely corrupt payments intended to improperly influence a recipient. The precise scope depends on the applicable framework, jurisdiction, and the definitions used by the relevant regulator or program, so practitioners should confirm which definition governs their context. This entry is educational and not legal or compliance advice.
Does a high improper payment figure automatically mean fraud has occurred?
Not necessarily. In many measurement frameworks, improper payments capture a range of causes, including administrative or documentation errors, and are not synonymous with confirmed fraud, which typically requires evidence of intent. Conflating the two can misstate the nature of the problem and misdirect the response. Determining whether a particular improper payment involves fraud generally depends on the specific facts, applicable legal standards, and professional judgment, and is often the subject of separate investigation. This entry does not draw factual or legal conclusions about any specific matter.
Which function typically owns the identification and remediation of improper payments?
Ownership generally depends on the organization's structure and the nature of the payment. Operationally, management and the relevant business or finance functions typically own the design and execution of controls that prevent and detect improper payments, consistent with first-line responsibility under commonly cited three-lines models. Compliance or risk functions generally provide oversight, monitoring, and advisory support, while internal audit typically provides independent assurance over control effectiveness rather than owning the controls themselves. The board or an appropriate committee generally exercises oversight rather than day-to-day operational responsibility. Specific allocation should be confirmed against the entity's own governance documents.
How can an organization distinguish between control design and operating effectiveness when addressing improper payments?
These are separate assessments and should not be treated interchangeably. Control design generally refers to whether a control, if operating as intended, would be capable of preventing or detecting an improper payment, for example, whether an approval or verification step exists at the right point. Operating effectiveness generally refers to whether that control actually functioned as designed over a period, for example, whether approvals were consistently obtained. A payment control can be well designed yet operate ineffectively, or operate consistently yet be poorly designed. Assessing both typically requires appropriate evidence and professional judgment about materiality and scope.
How does risk appetite inform an organization's approach to improper payments?
Risk appetite, the amount and type of risk an organization is generally willing to accept in pursuit of its objectives, can help management calibrate the intensity of controls, monitoring, and testing applied to payment processes, while recognizing that certain conduct may be prohibited outright by applicable law regardless of appetite. It is distinct from risk tolerance (acceptable variation around specific objectives) and risk capacity (the maximum risk the organization could bear). These distinctions should be preserved when setting thresholds. Where improper payments implicate binding legal requirements, appetite does not override those obligations, and the applicable standards should be confirmed for the relevant jurisdiction and sector.
What documentation typically supports the review of a suspected improper payment?
The specific documentation depends on the payment type, the controls in place, and applicable requirements, but organizations generally look to records that establish authorization, supporting evidence for the transaction, and adherence to required procedures, such as approvals, contracts or purchase records, invoices or supporting substantiation, and verification of the payee. The adequacy of documentation is generally assessed against the organization's own policies and any applicable regulatory or contractual requirements. This entry describes general categories only and does not prescribe what any particular organization must retain; requirements vary by jurisdiction, sector, and entity type.

Common misconceptions

If the payment was made by a third-party agent rather than the company itself, the company is not exposed.
In many jurisdictions liability can extend to payments made by intermediaries acting on the entity's behalf, particularly where there was knowledge, willful blindness, or inadequate due diligence. The routing of a payment through a third party does not, by itself, insulate the entity.
Small facilitation payments are universally permitted.
The treatment of facilitation payments differs across anti-bribery regimes. Some frameworks permit narrow exceptions while others prohibit such payments entirely, so acceptability depends on the applicable jurisdiction and law rather than a single global rule.
Improper payments are solely a compliance function concern.
Prevention typically involves the business (first line) operating controls, compliance (second line) designing and monitoring them, internal audit (third line) providing independent assurance, and the board providing oversight. Treating it as a single function's responsibility misstates where accountability sits.

Best practices

Conduct risk-based due diligence on third parties, intermediaries, and counterparties before engagement, with the depth of scrutiny calibrated to the assessed corruption risk of the relationship, geography, and sector.
Maintain accurate books and records and adequate internal accounting controls so that the nature and purpose of payments are transparently and correctly recorded.
Establish clear, written policies on gifts, hospitality, facilitation payments, and approvals, and confirm they are tailored to the jurisdictions and anti-bribery regimes applicable to the entity.
Clarify roles across the lines of defense so that the business operates controls, compliance monitors them, internal audit provides independent assurance, and the board or a designated committee exercises oversight.
Provide targeted training and reporting channels for employees and agents in higher-risk roles, and periodically test both the design and operating effectiveness of anti-corruption controls.
Consult qualified legal counsel on specific transactions or arrangements, as the acceptability of a given payment depends on the facts, the parties involved, and the applicable jurisdiction; these entries are educational and not legal, audit, or compliance advice.