Financial Crime

The First 24 Hours After Suspected Corporate Fraud

Controlling harm, preserving evidence and making defensible decisions

A suspected fraud can place an organisation in several legal positions at once. Craig MacKenzie explains how boards should control harm, preserve evidence and make defensible decisions without allowing urgency to harden suspicion into fact.

Author
Craig MacKenzie
Role
Partner and Solicitor Advocate
Published
27 July 2026
Reading time
21 minutes

Fraud rarely arrives with a complete set of facts. It may begin with an unexplained payment, a whistleblowing report, a suspicious supplier, an altered invoice, an unusual use of an AI system or a call that sounded exactly like a senior executive.

The first response often determines far more than whether money can be recovered. It may affect the integrity of the evidence, the organisation's exposure to criminal or regulatory action, the position of individual directors and employees, legal professional privilege, insurance cover, data protection obligations and the credibility of every account later given to investigators.

The central principle is simple:

Urgent action and suspended judgement are compatible.

An organisation does not need to decide within hours that a fraud has occurred. It does need to prevent further harm, preserve potentially relevant material and create a disciplined decision-making structure. The safest early response is active but evidence-led: contain what must be contained, preserve what may matter and avoid turning an allegation into an assumed fact.

This guide explains how boards, in-house lawyers and senior leaders should approach the first 24 hours after suspected corporate fraud in England and Wales. It is not a substitute for advice on a specific incident.

What should a company do first after discovering suspected fraud?

The immediate priorities are to:

  1. protect people, money, systems and data from continuing harm;
  2. preserve digital and physical evidence without altering or destroying it;
  3. establish a small, properly authorised response team;
  4. obtain independent legal advice and define who the lawyer acts for;
  5. record decisions, reasons and known uncertainties;
  6. assess urgent reporting, notification and asset-recovery obligations; and
  7. plan a proportionate investigation without alerting suspects unnecessarily.

These priorities overlap, but they are not interchangeable. Freezing an account may stop a loss. It may also alert a suspected insider. Disabling a user account may be necessary, but an unplanned shutdown may change metadata or prevent access to evidence. Interviewing a witness may produce useful information, but a poorly timed or leading interview can contaminate an account and prejudice a later criminal investigation.

The objective is not to solve the case on day one. It is to leave the organisation in a stronger evidential and strategic position at the end of day one.

Why the first 24 hours are unusually dangerous

The natural response to suspected fraud is to demand answers. Who did it? How much has been lost? Can the money be recovered? Who must be told?

Those are legitimate questions. The danger lies in answering them too quickly.

Early information is usually incomplete and may be misleading. A suspicious payment may be theft, an authorised transaction, a control failure or part of a wider scheme. An employee who appears responsible may have been deceived by a deepfake, had an account compromised, acted under instruction or committed deliberate fraud. The organisation may be the victim of one offence while an associated person has committed another offence intending to benefit it.

That distinction has become more important since the failure to prevent fraud offence came into force on 1 September 2025. Under section 199 of the Economic Crime and Corporate Transparency Act 2023, a large organisation may be criminally liable where an associated person commits a specified fraud offence intending to benefit the organisation or, in some circumstances, a person to whom it provides services. Senior management need not have ordered or known about the conduct. The organisation has a defence if it can prove that it had reasonable fraud prevention procedures in place, or that it was reasonable not to have such procedures.

The label attached to the incident therefore matters less than the facts preserved about it. An organisation may simultaneously need to investigate a loss, demonstrate the operation of its prevention procedures and consider whether the conduct created a benefit or intended benefit for the business.

The first strategic decision: who controls the response?

The response should be placed under clear authority immediately. In many cases, that will mean a small group consisting of:

  • a board or executive sponsor;
  • the general counsel or another senior legal lead;
  • specialist external criminal or regulatory counsel;
  • a forensic technology or cyber lead;
  • a finance or fraud-risk lead; and
  • HR, data protection, communications or insurance specialists when required.

The group should be no larger than necessary. Its members should know what they are authorised to decide, how decisions will be recorded and who will report to the board.

It is not enough to appoint the most senior people. They must be sufficiently independent. If the allegation concerns the finance director, the finance director cannot control the evidence-gathering exercise. If the general counsel advised on the transaction under scrutiny, the board may need separate legal advice. If competing interests emerge between the organisation and an individual director, one lawyer may not be able to advise both.

The first governance note should record:

  • how the concern arose;
  • the facts presently known;
  • what remains unverified;
  • the immediate risks identified;
  • who has authority to direct the response;
  • any actual or potential conflicts;
  • the purpose for which legal advice is being sought; and
  • the decisions taken, by whom and why.

This is not paperwork for its own sake. Months later, a regulator or prosecutor may assess the response with the benefit of information that nobody had on day one. A contemporaneous decision log shows what was known at the time and whether the response was rational, proportionate and properly supervised.

Preserve first, investigate second

Evidence preservation is not the same as collecting every document.

The first task is to prevent potentially relevant material from being changed, deleted or lost. Collection and review can then be planned. A rushed trawl through devices, inboxes and AI systems may itself alter evidence, breach access controls or create an incomplete and misleading dataset.

The preservation notice should be tailored to the suspected conduct but capable of expanding as the facts develop. It may need to cover:

  • email, messaging and collaboration platforms;
  • company and personal devices used for business;
  • accounting, payment and procurement systems;
  • access logs, audit trails and security alerts;
  • cloud storage and shared drives;
  • CCTV, call recordings and entry-control records;
  • contracts, invoices, expenses and bank information;
  • paper notes and notebooks;
  • telephone, WhatsApp or other off-platform communications;
  • AI prompts, outputs, conversation history and system logs;
  • model, account and workspace identifiers;
  • retrieved source material and uploaded files;
  • approval records, version histories and automated workflow logs; and
  • backups, retention settings and deletion schedules.

Automatic deletion and routine document destruction may need to be suspended. Relevant custodians should receive clear instructions not to delete, amend, forward or independently investigate material. The organisation should identify data held by third parties, including outsourced providers, cloud platforms, accountants and AI suppliers, and consider whether urgent preservation requests are required.

The SFO's corporate cooperation guidance identifies prompt preservation of relevant digital and hard-copy material as cooperative conduct. It also expects a self-reporting organisation to identify the whereabouts of key material and any risk that evidence may be destroyed. Preservation is therefore not merely an IT task. It may later form part of the evidence of how responsibly the organisation responded.

Do not press delete on the AI system

An AI-related incident creates evidence that traditional preservation plans may miss.

The visible output is only part of the record. The evidential picture may include the prompt, earlier iterations, system instructions, uploaded documents, retrieved sources, timestamps, user identity, access permissions, model version, tool calls, edits, exports and later human approvals.

Deleting an inaccurate or embarrassing output may feel like sensible containment. It may instead remove evidence showing:

  • what the user asked the system to do;
  • whether the output was relied upon or rejected;
  • whether a human altered it;
  • which information was available to the system;
  • whether safeguards operated;
  • whether the conduct was deliberate, reckless or innocent; and
  • whether the organisation's fraud prevention procedures worked in practice.

Preservation can protect the innocent as much as it assists an investigator. A generation trail may show that an employee challenged an output, followed the approval process or was deceived by fabricated material. A final document viewed in isolation may suggest dishonesty where the full record demonstrates the opposite.

The practical rule is:

Preserve the generation trail, not merely the final output.

Access can be restricted without destroying the record. Where continuing use creates a risk, the account, integration or workflow can be isolated in a forensically informed way while the underlying data is retained.

Contain the harm without contaminating the evidence

Containment is often necessary before the facts are clear. The method matters.

Potential steps may include:

  • pausing payments or changing approval thresholds;
  • asking a bank or payment provider to recall or freeze funds;
  • isolating a compromised account or device;
  • revoking tokens, sessions or remote access;
  • suspending an automated process;
  • protecting customers or counterparties from further loss;
  • separating a suspected employee from systems or duties; and
  • securing premises, documents or devices.

Before acting, the response team should ask:

  1. What continuing harm are we trying to stop?
  2. Could this step alert a suspect or cause evidence to disappear?
  3. Will it alter logs, metadata or device contents?
  4. Can the risk be controlled by restricting access rather than deleting data?
  5. Who should record the action and its technical effect?
  6. Is urgent court, banking or law-enforcement intervention required?

Where money has been transferred, minutes may matter. Banks, payment providers, insurers and specialist civil fraud lawyers may need to be engaged urgently. Depending on the case, freezing relief, proprietary injunctions, disclosure orders or other asset-tracing measures may be available. The criminal, civil and regulatory strategies should be coordinated. A step designed to recover assets can affect whether a suspect is alerted, what is said to a third party and how evidence is later obtained.

Do not begin with a round of interviews

Interviewing everyone immediately is a common but serious error.

The first account of a witness may be especially important. If witnesses are brought together, shown the same documents or told the organisation's developing theory, their recollections may converge. A suspect who is interviewed prematurely may be alerted to the evidence, contact others or destroy material. An internal interviewer may ask questions that are leading, accusatory or based on false assumptions.

Before any substantive interview, decide:

  • whether the person is a witness, potential suspect or both;
  • whether immediate welfare or safeguarding information is required;
  • what documents should be secured first;
  • whether law enforcement may wish to obtain the first account;
  • whether the person needs independent legal advice;
  • whether an employment process is running alongside the investigation;
  • how the interview will be recorded; and
  • whether the interview record may later be disclosed or privilege asserted.

The SFO's cooperation guidance expressly encourages early engagement about the parameters of an internal investigation. It warns against steps, particularly internal interviews, that may prejudice its investigation. The guidance also notes the risk of evidence being destroyed or first accounts being delayed in a way that creates an opportunity for fabrication.

This does not mean that nobody can be spoken to. Short, carefully controlled enquiries may be necessary to identify an immediate threat, locate evidence or stop a payment. They should not drift into an unplanned accusatory interview.

The allegation and the person are not the same thing

Organisations often move too quickly from "we have found an irregularity" to "we have found the fraudster".

That can damage both the investigation and the people involved. An employee may have made an error, followed a compromised instruction, been manipulated through social engineering or raised the concern themselves. Conversely, a person who appears cooperative may be involved in a wider scheme.

Neutral language is therefore strategically important. Early records should use terms such as "concern", "suspected conduct", "potential loss" and "unverified allegation" where those descriptions are accurate. Communications should distinguish evidence from inference.

Employment action may still be necessary. Suspension can be a neutral protective measure, but it should be considered carefully, documented and coordinated with employment advice. The organisation must also protect whistleblowers from retaliation and limit disclosure of their identity to those who genuinely need to know.

Fairness is not an obstacle to an effective investigation. It is one of the conditions of one.

Reporting is a decision process, not a reflex

Some notifications are mandatory and time-critical. Others involve a strategic judgement. They should be put on a single reporting matrix recording:

  • the potential recipient;
  • the legal or contractual basis;
  • the trigger for notification;
  • the applicable deadline;
  • the facts required;
  • who will decide;
  • the risks of delay;
  • the risks of an inaccurate or incomplete report; and
  • whether notification to one body affects reporting to another.

Possible recipients include:

  • the Serious Fraud Office;
  • police or the National Crime Agency;
  • Action Fraud;
  • the Financial Conduct Authority or another sector regulator;
  • the Information Commissioner's Office;
  • banks and payment providers;
  • insurers;
  • auditors;
  • contracting authorities or commercial counterparties; and
  • overseas authorities.

A report to one body is not necessarily a report to another. The SFO guidance states, for example, that a Suspicious Activity Report or a report to another agency is not a self-report to the SFO unless the conduct is also reported to the SFO simultaneously or immediately afterwards.

The SFO now says that a prompt self-report and full cooperation will ordinarily lead to an invitation to negotiate a deferred prosecution agreement rather than prosecution, unless exceptional circumstances apply. It also recognises that an organisation may need to investigate unclear suspicions before reporting and does not expect a full investigation to be completed first.

That does not make self-reporting automatic. The organisation must understand, as far as reasonably possible:

  • what conduct is suspected;
  • whether there is direct evidence or only an anomaly;
  • who may be involved;
  • whether the conduct could amount to corporate offending;
  • whether it intended to benefit the organisation;
  • which jurisdictions and agencies are engaged;
  • whether evidence or assets are at immediate risk; and
  • what can responsibly be said at that stage.

The guiding principle is:

A self-report is a strategic act, not a confession impulse.

Delay can be damaging, but so can an ill-defined allegation sent to the wrong authority without a plan for what follows.

Failure to prevent fraud: secure the evidence of prevention

When suspected conduct could engage section 199 ECCTA, organisations often focus exclusively on proving what the associated person did. They should also preserve the evidence showing what the organisation had done to prevent it.

The statutory defence concerns reasonable procedures in place at the time of the fraud. Relevant material may include:

  • the fraud risk assessment and its approval history;
  • policies and procedures;
  • training records and attendance data;
  • due diligence on agents, suppliers and other associated persons;
  • delegated authorities and payment controls;
  • monitoring, audit and testing results;
  • prior incidents and lessons learned;
  • reports to senior management;
  • resourcing decisions;
  • whistleblowing arrangements;
  • disciplinary and remediation records; and
  • evidence showing whether controls operated in practice.

Do not rewrite the historical record. Remediation should begin where necessary, but later improvements must be clearly distinguished from the procedures that existed when the suspected conduct occurred.

The Home Office guidance is organised around six principles: top-level commitment, risk assessment, proportionate risk-based prevention procedures, due diligence, communication including training, and monitoring and review. Those principles provide a useful preservation map as well as a compliance framework.

Control communications before the story controls the organisation

Internal and external communications can create evidence, trigger legal duties and affect reputations. They can also compromise the investigation.

A controlled communications plan should identify:

  • who needs to know now;
  • what can accurately be said;
  • who is authorised to communicate with staff, customers, the media and authorities;
  • how whistleblower confidentiality will be protected;
  • whether communications require legal review; and
  • how questions and responses will be recorded.

Avoid broad email chains, speculative messages and labels such as "the fraudster". Do not promise an outcome or announce that an allegation is proven. Do not use a public relations response as a substitute for a legal and evidential strategy.

The correct message is often limited: a concern has been identified; steps are being taken to protect the organisation and preserve evidence; the facts are being established; and enquiries should be directed to a named person.

What should the board know by the end of the first day?

The board may not have answers to every question. It should have a reliable picture of the response.

By the end of the first 24 hours, decision-makers should ordinarily know:

  • what triggered the concern;
  • what is fact, what is inference and what remains unknown;
  • whether harm is continuing;
  • what containment action has been taken;
  • what evidence has been preserved and what remains at risk;
  • who controls the investigation;
  • whether conflicts require separate representation;
  • which urgent notification deadlines may apply;
  • whether funds or assets may still be recoverable;
  • what the next investigative steps are; and
  • when the position will be reviewed.

The board should also be able to see the decisions it has deliberately deferred. "Not yet decided" can be a defensible position if the reason, evidential gap and review point are recorded.

A practical first-day chronology

The first hour

  • Escalate the concern to the designated legal or incident lead.
  • Assess immediate danger to people, funds, systems and data.
  • Stop continuing loss where that can be done safely.
  • Preserve obvious sources of evidence and suspend relevant deletion.
  • Limit discussion to those who need to know.
  • Record the initial facts in neutral language.

Hours one to four

  • Establish authority, independence and legal representation.
  • Identify potential suspects, witnesses, custodians and conflicts.
  • Coordinate legal, forensic, banking and cyber expertise.
  • Issue proportionate preservation instructions.
  • Secure AI records, logs and third-party data.
  • Consider urgent asset recovery and notification deadlines.

Hours four to twelve

  • Build an initial event chronology.
  • Separate verified facts from assumptions.
  • Map criminal, regulatory, civil, employment, data and insurance issues.
  • Decide whether any immediate witness contact is necessary.
  • Review whether containment has altered or endangered evidence.
  • Prepare an initial briefing for the board or authorised committee.

Hours twelve to twenty-four

  • Approve the investigation scope and reporting lines.
  • Confirm the collection and review plan.
  • Create the notification matrix.
  • Preserve evidence of fraud prevention procedures.
  • Identify decisions that require further facts or specialist advice.
  • Set review points for the next 24 hours, seven days and beyond.

Ten mistakes that weaken the response

  1. Assuming the allegation is already proved. This encourages confirmation bias and unfair treatment.
  2. Deleting suspicious AI content or disabling systems without forensic advice. Containment can destroy the generation trail or technical evidence.
  3. Interviewing the obvious suspect immediately. This may alert others, contaminate accounts or prejudice a law-enforcement investigation.
  4. Allowing an implicated executive to control the response. Authority without independence undermines credibility.
  5. Copying a lawyer into every email and assuming privilege follows. Privilege depends on purpose and substance.
  6. Treating the company and its directors as having identical interests. Their positions may conflict.
  7. Focusing only on the loss. The organisation may also face corporate, regulatory or contractual exposure.
  8. Reporting reflexively without identifying the legal trigger or strategy. An inaccurate first account can be difficult to correct.
  9. Rewriting policies after the event without preserving historic versions. This may destroy evidence relevant to the statutory defence.
  10. Failing to keep a decision log. A sound decision that cannot later be explained may look like an arbitrary one.

Frequently asked questions

Should a suspected employee be suspended immediately?

Not automatically. Suspension may be necessary to protect evidence, people or systems, but it should be a proportionate and documented measure. Consider whether access can be restricted, whether suspension would alert others, and whether employment advice is required.

Should the company call the police straight away?

Sometimes. Immediate police involvement may be appropriate where there is continuing danger, urgent risk to evidence, significant criminality or a need for powers the company does not possess. In other cases, a short period of legally directed fact-finding may be justified. Mandatory and time-critical reporting duties must still be met.

Can the company search an employee's email or device?

Possibly, but ownership of the device does not answer every question. The organisation must consider its policies, the employee's privacy rights, data protection, the scope of consent, access controls, employment law and the need for forensic integrity. Personal devices and messaging accounts require particular care.

Does reporting to Action Fraud amount to a self-report to the SFO?

No. The SFO states that reporting through a Suspicious Activity Report or to another agency does not amount to an SFO self-report unless the suspected offending is also reported to it simultaneously or immediately afterwards.

Must the company finish its internal investigation before approaching the SFO?

No. The SFO says it does not expect a company to complete a full investigation before self-reporting. Direct evidence of corporate offending may require a prompt report. Where the position is less clear, some further investigation may be reasonable.

Is every suspicious AI output evidence of fraud?

No. An output may be wrong, manipulated, misunderstood or never acted upon. The relevant questions include who generated it, what they asked, what information the system used, what happened to the output and whether dishonest human conduct can be proved. That is why the full generation and decision trail should be preserved.

What is the most important document created on day one?

Usually the contemporaneous decision log. It should record what was known, what was uncertain, what action was taken, who authorised it and why. It creates discipline during the incident and accountability afterwards.

Final perspective

The first 24 hours are not a race to produce a culprit or a confession. They are a test of whether the organisation can act decisively without allowing urgency to distort judgement.

The strongest response does four things at once:

  • it controls continuing harm;
  • it preserves the truth in its original form;
  • it protects the legal positions of the organisation and affected individuals; and
  • it creates a defensible route to the decisions that follow.

Fraud investigations are often judged retrospectively. The facts become clearer, the chronology looks inevitable and early uncertainty is forgotten. A disciplined first-day response resists that distortion. It records what was actually known, preserves what may later matter and ensures that speed does not become carelessness.

Act urgently. Decide carefully. Preserve both the evidence and the options.

A suspected fraud requires immediate control, but not premature conclusions.

If your organisation has identified suspicious conduct, Craig MacKenzie can provide urgent strategic advice through Forbes Solicitors on evidence preservation, internal investigations, individual and corporate exposure, and engagement with investigators or regulators.

Request a confidential consultation

Do You Require Advice About Your Circumstances?

This material provides general information and is not a substitute for advice about a specific investigation or case.

Craig provides legal services exclusively through Forbes Solicitors. To make an initial enquiry, contact Craig at:

craig.mackenzie@forbessolicitors.co.uk

07976 258 258

An enquiry does not constitute an instruction. Forbes Solicitors must confirm in writing that it has accepted the matter before any solicitor–client relationship arises.

Related Guidance