What Happened?
Victoria's Independent Broad-based Anti-corruption Commission (IBAC) charged a former senior National Gallery of Victoria (NGV) employee with eight offences — seven counts of theft and one count of misconduct in public office — the watchdog announced on 24 September 2026.
The charges follow Operation Sonder, an IBAC investigation opened in September 2025 into alleged corrupt conduct, theft and misuse of position by the former employee. IBAC alleges that between September 2019 and September 2025, mobile phones were purchased under an NGV account to the value of approximately $8 million and then sold for personal financial benefit.
IBAC further alleges the employee misused his position to conceal the conduct. NGV reported the matter to Victoria Police and IBAC in September 2025 and terminated the employee; a gallery spokesperson said the purchases were never authorised, and the gallery has since introduced new controls. The former employee is expected to appear before Melbourne Magistrates' Court on 20 October 2026, and the allegations have not been tested in court.
Where Was the Supplier Risk?
This didn't need a fake supplier or a hacked payment. The phones were bought through the gallery's own account with what looks, on its face, like an ordinary telecom bill — the exposure sat in who could authorise the spending and whether anyone independent was watching it accumulate.
Six years is the detail that should worry procurement and AP teams most. One unauthorised purchase is a control gap; the same pattern repeating for six years undetected is evidence that no independent process was ever comparing account activity against what the business actually expected to spend.
IBAC alleges the employee didn't just make the purchases — he worked to conceal them. A control that only catches misuse when someone confesses or a third party happens to notice isn't really monitoring anything; it's waiting to get lucky.
What Went Wrong?
Purchasing authority on the account wasn't independently reviewed against actual business need, so spending could accumulate under one person's control without a second set of eyes checking it.
Nothing appears to have flagged an escalating, sustained pattern of high-value purchases on a single account as an exception worth investigating — the volume went unnoticed for years, not just one transaction.
The alleged conduct came to light only after it was reported internally in September 2025, not because a monitoring process surfaced it — meaning six years of activity depended entirely on the person responsible for it not being questioned.
What Should Businesses Do?
Cap and review purchasing authority independently of the person using it
An account able to accumulate millions in spending over years needs a second, independent approver who isn't the same person requesting or authorising the purchases — not just a nominal sign-off from someone who trusts the requester.
Flag sustained or escalating spend on an account as an exception, not a trend
A pattern that grows quietly over years is exactly what payment exception monitoring is built to catch — reviewing unusual volume and value against expected business activity, rather than waiting for a single transaction to look wrong.
Keep purchasing and approval records independently auditable
Six years of purchases under one account should leave a trail reviewable by someone other than the person who created it. Independently retrievable documentation is what lets a pattern surface on schedule, not by chance.
Don't rely on self-reporting to catch insider misuse
This case only came to light because it was reported internally — a control that depends on the person responsible deciding to disclose it isn't a control. Independent monitoring needs to work without anyone volunteering the truth.
The ArayaPRO Response
How ArayaPRO Helps
This is exactly the type of supplier risk ArayaPRO is built to control.
Further Reading
Sources
- ABC News report · 24 September 2026 · Read original article →
