Financial Crime · Strategic Guide
Self-Reporting, SFO Cooperation and Deferred Prosecution Agreements
Discovering suspected corporate wrongdoing creates immediate pressure to report, explain and reassure. None of those steps should be improvised. Craig MacKenzie explains how organisations should decide whether and when to self-report, what genuine cooperation with the Serious Fraud Office requires, how privilege and individual exposure affect the strategy, and why a Deferred Prosecution Agreement remains a judicially controlled outcome rather than a negotiated entitlement.
- Author
- Craig MacKenzie
- Role
- Partner and Solicitor Advocate
- Published
- 27 July 2026
- Reading time
- 29 minutes
The decision is not simply whether to report
When an organisation discovers suspected fraud, bribery or related economic crime, the apparent choice can seem binary:
- report immediately and seek credit for openness; or
- investigate first and risk being accused of delay.
That framing is too crude.
The real task is to control several decisions at once:
- what is known, suspected and still unverified;
- whether the conduct may amount to a criminal offence;
- which individual and corporate liability routes may apply;
- whether any law, regulatory rule, contract or market obligation requires notification;
- which authority or authorities may need to be told;
- whether assets, data or first accounts are at immediate risk;
- what can properly be said without speculation;
- how privilege and individual conflicts will be protected;
- whether an internal investigation may prejudice a criminal investigation;
- how the organisation will continue to cooperate after the first report; and
- what outcome is realistically available.
A self-report can be strategically powerful. It can also disclose the existence of suspected criminal conduct, identify witnesses and evidence, trigger compulsory powers, accelerate parallel investigations and create statements against which every later account will be measured.
The central principle is:
Self-reporting is not a confession. It is a controlled disclosure of verified facts, known risks and the organisation’s response.
The objective is not to delay until certainty exists. Nor is it to report an allegation as though it were a proved offence. It is to reach a defensible decision promptly, preserve the evidence and communicate with precision.
What a self-report can and cannot achieve
A self-report is not one legally uniform act. Its meaning depends on the recipient, the reporting regime and the conduct disclosed.
Reporting to the Serious Fraud Office may influence whether a corporate is prosecuted or invited to negotiate a Deferred Prosecution Agreement. Reporting to the Financial Conduct Authority may discharge a regulatory notification obligation. A Suspicious Activity Report may address money-laundering concerns. A personal-data breach report to the Information Commissioner’s Office may satisfy a separate data-protection duty. Contractual notifications may be required to insurers, lenders, auditors, customers or public bodies.
One report does not necessarily satisfy another obligation.
The SFO’s April 2025 Cooperation Guidance is explicit that reporting through a Suspicious Activity Report or to another domestic or foreign agency is not treated as a self-report to the SFO unless the suspected offending is also reported to the SFO simultaneously or immediately afterwards.
The organisation should therefore create a reporting map, not assume that one notification reaches every relevant authority.
A self-report may help
A prompt and properly managed report may:
- demonstrate responsible corporate conduct;
- preserve the possibility of a DPA;
- influence the public-interest decision on prosecution;
- support mitigation at sentence;
- establish credibility with investigators and regulators;
- enable coordination before evidence is collected or witnesses are interviewed;
- reduce the risk that another person reports first;
- demonstrate that the board has taken ownership;
- support recovery, restraint or protection of assets; and
- provide a framework for remediation.
A self-report does not guarantee
It does not guarantee:
- that the SFO will decline to investigate;
- that compulsory powers will not be used;
- that individuals will be protected;
- that a DPA invitation will be made;
- that DPA negotiations will succeed;
- that a court will approve the proposed agreement;
- that another regulator or overseas authority will adopt the same outcome;
- that civil claims, debarment or reputational consequences will be avoided; or
- that information disclosed will remain confidential.
The board should understand both sides before treating self-reporting as a route to a predetermined resolution.
The SFO’s current position
The 2025 Cooperation Guidance gives corporates a clearer enforcement signal than earlier guidance.
It states that:
- a prompt self-report always weighs heavily in favour of a DPA over prosecution;
- if a corporate self-reports promptly and cooperates fully, the SFO will invite it to negotiate a DPA rather than prosecute unless exceptional circumstances apply;
- a corporate which did not self-report may still be considered for DPA negotiations if its later cooperation is exemplary;
- a knowing failure to report promptly can affect the assessment of cooperation and mitigation;
- failure to notify suspected offending within a reasonable time is a public-interest factor in favour of prosecution; and
- the SFO does not expect the organisation to complete a full investigation before reporting.
This is significant, but its limits matter.
First, the guidance concerns the SFO’s exercise of prosecutorial discretion. It does not amend Schedule 17 to the Crime and Courts Act 2013, create an enforceable right to a DPA or bind the court.
Secondly, an invitation to negotiate is not a DPA. Negotiations may expose disagreement about the facts, legal characterisation, penalty, disgorgement, compliance terms, costs or cooperation.
Thirdly, a DPA can take effect only if the Crown Court declares that it is in the interests of justice and that its terms are fair, reasonable and proportionate.
Fourthly, the guidance preserves an exception. Seriousness, repeated misconduct, management involvement, obstruction, weak remediation or other circumstances may still point towards prosecution.
The practical message is powerful but qualified:
Prompt reporting can secure a route to negotiation. It cannot secure the destination.
When does the reporting clock begin?
There is no universal statutory clock for an SFO self-report. The SFO speaks of reporting within a “reasonable time” after suspected offending comes to light. What is reasonable depends on the circumstances.
The question should not be reduced to the date of the first allegation.
Relevant milestones may include:
- receipt of a whistleblowing report;
- detection of an anomalous transaction;
- discovery of a false document or hidden communication;
- confirmation that an employee, agent or intermediary acted dishonestly;
- receipt of credible information from an auditor, regulator or third party;
- identification of direct evidence of corporate offending;
- board or committee escalation; and
- emergence of sufficient facts to identify the suspected offence and responsible actors.
An uncorroborated allegation may justify preservation and urgent scoping without yet supporting a responsible criminal self-report. Direct evidence of corporate offending may require much faster action.
The SFO recognises that an organisation may need to investigate suspicions sufficiently to understand the nature and extent of the possible offending. It also makes clear that a full internal investigation is not expected before reporting.
That creates a narrow but important investigation window.
The organisation should use it to answer the questions necessary for a responsible report, not to complete every issue that an eventual prosecution might examine.
The minimum viable investigation
Before deciding whether and how to approach the SFO, the organisation will usually need a rapid, privileged assessment.
The minimum viable investigation should ordinarily establish:
- The allegation What exactly is said to have happened? Separate the source’s words from later interpretation.
- The potentially relevant offence Is the concern fraud, bribery, false accounting, money laundering, failure to prevent fraud or another offence? What conduct and mental elements would need to be proved?
- The people involved Who acted, approved, knew, challenged or benefited? Are any senior managers or associated persons potentially involved?
- The entity map Which legal entity employed, instructed, paid or received the benefit? Do not use the group name as a substitute for entity analysis.
- The jurisdictional connections Where did the acts, communications, decisions, payments and effects occur? Which other authorities may have an interest?
- The evidence at risk Are messages disappearing, accounts being closed, devices leaving the organisation, assets moving or witnesses coordinating accounts?
- The reporting obligations Is any notification mandatory, time-limited or required under a regulatory or contractual regime?
- The immediate controls What must stop now? Consider payment holds, access restrictions, preservation notices, segregation of duties and suspension of risky relationships.
- The degree of confidence Which facts are verified, which are reasonably suspected, which remain disputed and which are unknown?
The output should be a decision document, not a premature prosecution brief.
It should record:
- the information available at the time;
- the steps taken to test it;
- the legal advice received;
- the risks of reporting and not reporting;
- the decision-maker;
- the decision reached;
- any trigger for reconsideration; and
- the timetable for the next review.
This contemporaneous record may later be critical. It can show that time was used to understand and preserve the matter, rather than to conceal or tactically delay it.
Mandatory notification and voluntary self-reporting are different
The phrase “self-report” can obscure the difference between a legal duty and a strategic choice.
Depending on the organisation and facts, potential reporting routes may include:
- the SFO;
- the FCA or Prudential Regulation Authority;
- a sector regulator;
- the National Crime Agency through the Suspicious Activity Reports regime;
- the ICO for a qualifying personal-data breach;
- Companies House or a market operator;
- overseas prosecutors and regulators;
- insurers;
- auditors;
- contractual counterparties; and
- public-procurement authorities.
Each route has its own trigger, timescale, content and consequences.
For an FCA-regulated firm, the duty to deal with regulators openly and cooperatively and the notification provisions in the FCA Handbook may require disclosure before the organisation has resolved whether to make a voluntary SFO self-report.
A Suspicious Activity Report has a different purpose. It may be needed where a person in the regulated sector knows or suspects money laundering, and a defence against money laundering may be sought for a proposed act. It should not be treated as a corporate criminal-resolution mechanism.
Data-protection notification may operate on an even shorter timetable where a personal-data breach is likely to create a risk to individuals.
The reporting map should therefore identify:
| Question | Required analysis |
|---|---|
| Who must be told? | Every regulator, prosecutor, law-enforcement body and contractual recipient potentially engaged |
| Why? | Statutory duty, regulatory rule, consent request, contract, policy or voluntary cooperation |
| By when? | Fixed deadline, promptness standard or event-driven trigger |
| About what? | Verified facts, suspected conduct, affected data, transactions, people and entities |
| In what form? | Portal, prescribed form, written notification, oral contact or secure production |
| With whose authority? | Board, committee, general counsel, money-laundering reporting officer or another designated person |
| What follows? | Update duties, consent process, compulsory request, interview, production or remediation |
The aim is coordination without conflation.
Who should make the decision?
The reporting decision should be owned at the correct level and insulated from conflicted individuals.
Depending on the organisation, responsibility may sit with:
- the board;
- an independent board committee;
- the audit or risk committee;
- the general counsel;
- the money-laundering reporting officer;
- a regulated senior manager; or
- another authorised decision-maker.
The correct structure depends on the suspected involvement.
If a senior executive may be implicated, that person should not control the investigation, select what the board sees or participate in deciding whether their own conduct is reported. If the general counsel gave advice on the transaction under review, independent advice may be required. If the alleged conduct benefits one entity at the expense of another, group-level instructions may conceal separate interests.
The organisation should define:
- who the legal client is;
- who may instruct external lawyers;
- who receives privileged advice;
- who decides on reporting;
- who communicates with authorities;
- who controls public statements; and
- how individual representation will be handled.
Governance is part of the evidence. Investigators may later examine who knew what, when concerns were escalated and whether the decision process was genuinely independent.
What should the first SFO report contain?
The SFO expects a corporate self-report to identify all relevant known facts and evidence concerning the suspected offences, the individuals involved inside and outside the organisation, and the relevant jurisdictions. It should enable the SFO to understand the nature and extent of the suspected offending.
The SFO also expects information about:
- the location of key material;
- risks that evidence may be destroyed;
- risks that assets may dissipate; and
- the proposed format for digital material, which should be agreed before production.
A disciplined first report should usually distinguish four categories.
1. Verified facts
These are matters supported by identified material or reliable first-hand evidence, such as:
- a payment was made on a particular date;
- an invoice contains a specified statement;
- an account belonged to a named entity;
- a message was sent from an identified system;
- a person held a defined role; or
- a transaction was approved through a particular process.
2. Reasonable suspicions
These are inferences that warrant investigation but are not yet established, such as:
- an intermediary may have concealed the true recipient;
- a representation may have been dishonest;
- a senior manager may have known that figures were false; or
- a payment may have been intended to influence a public official.
3. Disputed matters
The report should not erase credible alternative accounts. If a person denies knowledge, an approval was arguably ambiguous or the legal characterisation is contested, say so accurately.
4. Known unknowns
Identify material gaps:
- inaccessible overseas records;
- missing devices;
- unidentified beneficiaries;
- unresolved authorship;
- incomplete transaction data;
- pending forensic work; or
- witnesses not yet interviewed.
This structure protects credibility. It enables the organisation to be candid without presenting provisional analysis as an admission.
What genuine cooperation requires
The SFO defines cooperation as assistance which goes above and beyond what the law requires.
Compliance with a compulsory notice is required by law. It is not, by itself, exemplary cooperation. Equally, requesting a section 2 notice for a legitimate reason is not automatically treated as uncooperative.
The 2025 guidance identifies conduct likely to demonstrate exemplary cooperation, including:
- prompt preservation of relevant digital and hard-copy material;
- identification and collection of relevant documents and information;
- identification of custodians and locations;
- production of overseas documents within the organisation’s control;
- identification of relevant third-party material;
- provision of translations;
- presentation of the facts and identification of people involved;
- early engagement about the scope of any internal investigation;
- advance notice of proposed investigative steps which may affect the SFO;
- timely updates and key findings;
- provision of facts gathered through the internal investigation;
- provision of non-privileged interview records;
- consideration of waiver where interview records are privileged;
- refraining from interviews at the SFO’s request;
- disclosure of other regulatory or prosecutorial interest;
- information about earlier relevant corporate conduct;
- details of disciplinary action and personnel changes;
- financial analysis of benefit and harm;
- analysis of the compliance programme at the time and remediation since; and
- assistance in facilitating access to employees, with independent legal advice where appropriate.
This is not a checklist to be performed mechanically.
Cooperation must be:
- accurate;
- timely;
- organised;
- proportionate;
- legally informed;
- consistent across jurisdictions; and
- sustained over time.
An impressive first presentation followed by delay, selective disclosure or evasiveness is not genuine cooperation.
The SFO identifies tactical delay, obscuring individual involvement, minimising the extent of offending, forum shopping and overwhelming investigators with undifferentiated data as examples of uncooperative conduct.
The practical test is:
Does the organisation make the investigation more reliable, or merely make itself appear helpful?
Cooperation is not capitulation
A corporation can cooperate genuinely while:
- challenging an incorrect legal analysis;
- preserving a valid claim to privilege;
- explaining why material is outside its control;
- seeking a compulsory notice where production requires legal authority;
- protecting personal data and foreign-law restrictions;
- correcting inaccurate assumptions;
- identifying exculpatory material;
- ensuring employees receive independent advice;
- declining to adopt an allegation as fact; and
- negotiating fair and proportionate terms.
Cooperation does not require the organisation to abandon its legal rights or accept liability that the evidence does not establish.
The distinction is between principled protection and tactical obstruction.
That line should be documented. If a production is delayed by a blocking statute, data-protection restriction, privilege review or technical collection problem, the organisation should explain the problem early, propose a lawful solution and keep the SFO updated.
Silence allows a legitimate difficulty to look like resistance.
Privilege: preserve it before deciding whether to waive it
The SFO states that an organisation will not be penalised for maintaining a valid claim to legal professional privilege. It also states that waiver is a significant cooperative act and may help expedite an investigation.
Those propositions must be held together.
Privilege should not be waived casually, globally or before the organisation understands:
- whether privilege validly attaches;
- the precise document or category concerned;
- the purpose of the proposed waiver;
- whether a limited waiver is legally and practically sustainable;
- the effect in civil litigation;
- the position in other jurisdictions;
- the consequences for individuals;
- whether the material is accurate and complete;
- whether related communications may also be exposed; and
- whether the organisation can provide the underlying facts without waiving legal advice.
The right approach is staged.
Stage one: establish the privilege architecture
Define the client, purpose, legal team, investigation team and communication protocols. Keep legal advice distinct from routine business communications, employment decisions and public-relations work.
Stage two: identify what is fact and what is advice
Facts do not become privileged simply because they are communicated to a lawyer. The organisation may be able to provide the facts gathered while maintaining privilege over legal advice.
Stage three: assess the category
Legal advice privilege and litigation privilege have different requirements. An interview note is not privileged merely because a lawyer created it. The claim must be analysed against the actual purpose and circumstances.
Stage four: decide waiver document by document or category by category
The decision should consider the criminal, regulatory, civil and cross-border consequences together.
Stage five: record the basis
If privilege is maintained, waived or disputed, record the legal basis, scope and decision-maker.
The central safeguard is:
Preserve privilege first. Decide waiver later.
Once confidentiality is lost, it may not be recoverable.
Internal investigations after a report
An organisation may need to continue investigating after approaching the SFO. It should not assume that it remains free to proceed as if no criminal investigation existed.
The SFO expects early engagement about the investigation’s parameters and advance notice of steps which may prejudice its work, particularly interviews.
The concern is practical. An internal interview can:
- alert a suspect to the evidence;
- allow accounts to be coordinated;
- delay investigators obtaining an uncontaminated first account;
- prompt destruction or concealment;
- generate a statement relevant to disclosure;
- affect an employee’s legal position; and
- complicate the admissibility or reliability of later evidence.
This does not mean every internal step must stop. The organisation may still need to:
- protect customers or markets;
- satisfy regulatory duties;
- make employment decisions;
- secure systems;
- understand ongoing risk;
- report to its board or auditor; and
- remediate deficient controls.
The solution is a written investigation protocol that identifies:
- steps requiring prior SFO engagement;
- steps the organisation may take without notice;
- urgent exceptions;
- interview sequencing;
- information barriers;
- preservation responsibilities;
- privilege treatment;
- update frequency; and
- responsibility for resolving conflicts.
The full methodology is addressed in Internal Investigations: Privilege, Interviews and Evidence Contamination.
Individuals and the corporate cooperation strategy
The interests of an organisation and its current or former personnel may diverge rapidly.
The organisation may seek credit by:
- identifying individuals involved;
- providing communications and records;
- describing failures of supervision;
- facilitating interviews;
- taking disciplinary action; or
- agreeing a statement of facts.
An individual may dispute:
- authorship;
- knowledge;
- dishonesty;
- authority;
- the meaning of communications;
- the accuracy of interview records;
- the organisation’s account of governance; or
- whether they acted for the company at all.
The corporate should not use individuals as bargaining material. Nor should it conceal their apparent involvement to protect them.
Sound management requires:
- early conflict analysis;
- separate legal representation where appropriate;
- clear interview warnings;
- no suggestion that the organisation’s lawyers act for an individual unless they do;
- careful control of joint-defence or common-interest arrangements;
- independent decisions on employment and discipline;
- fair preservation of material supporting and undermining allegations; and
- scrutiny of any proposed statement of facts affecting uncharged people.
Corporate cooperation and individual justice are not opposites. A reliable investigation should protect both.
What is a Deferred Prosecution Agreement?
A DPA is a statutory agreement between a designated prosecutor and an organisation facing alleged economic or related criminal offending.
It is available only to organisations, not individuals.
Under Schedule 17 to the Crime and Courts Act 2013:
- the prosecutor formulates a bill of indictment;
- the Crown Court declares that the proposed DPA is in the interests of justice and its terms are fair, reasonable and proportionate;
- the indictment is preferred and proceedings are automatically suspended;
- the organisation complies with the agreed terms for the specified period; and
- if the DPA is completed, the proceedings are discontinued.
If the organisation materially breaches the agreement, the court may invite the parties to agree a remedy or terminate the DPA. Termination can allow the suspended prosecution to resume.
A DPA is therefore not:
- an acquittal;
- a private settlement;
- an agreement to ignore wrongdoing;
- an immunity arrangement for individuals; or
- a result the organisation can demand.
It is a public, court-supervised resolution of alleged corporate criminal conduct.
The evidential and public-interest tests
The DPA Code of Practice requires the prosecutor to apply an evidential stage and a public-interest stage.
The evidential stage
The prosecutor must be satisfied either that:
- the evidential stage of the Full Code Test is met; or
- there is at least a reasonable suspicion, based on some admissible evidence, that the organisation committed the offence, with reasonable grounds to believe that continued investigation would produce further admissible evidence within a reasonable period so that the Full Code Test could be met.
This alternative threshold permits DPA discussions before every evidential issue has been completed. It does not permit a DPA without a proper evidential foundation.
The public-interest stage
The prosecutor must be satisfied that the public interest is properly served by a DPA rather than prosecution.
Factors favouring prosecution may include:
- serious or systemic offending;
- substantial harm;
- a history of similar conduct;
- conduct forming part of established business practices;
- failure to notify within a reasonable time;
- ineffective compliance despite earlier warnings; and
- obstruction or a poor response.
Factors favouring a DPA may include:
- prompt self-reporting;
- full and genuine cooperation;
- absence of similar history;
- a proactive and effective compliance programme;
- replacement or discipline of responsible individuals;
- significant remediation;
- a change in corporate culture;
- disproportionate collateral consequences; and
- the availability of compensation and effective future controls.
No factor is automatically decisive. The prosecutor balances the seriousness, culpability, harm, response and public interest in the individual case.
The court is not a rubber stamp
The court’s role is fundamental.
Before a DPA is finalised, the prosecutor must seek a preliminary declaration that entering the proposed agreement is likely to be in the interests of justice and that its proposed terms are fair, reasonable and proportionate.
The final agreement requires a further declaration applying those tests.
The court may examine:
- the seriousness and duration of offending;
- senior-management involvement;
- the organisation’s cooperation;
- the timing and quality of any self-report;
- prior misconduct;
- remediation;
- corporate change;
- the proposed financial penalty;
- disgorgement and compensation;
- compliance obligations;
- the treatment of individuals;
- consistency with sentencing principles; and
- the public interest in transparent justice.
The judicial role explains why neither the SFO nor the organisation can promise a DPA outcome in advance.
Published judgments, including the approval of the Airbus DPA, show that the court scrutinises the scale of wrongdoing, cooperation, transformation, penalty and international context rather than approving a bargain merely because both parties support it.
What terms can a DPA contain?
Schedule 17 provides a non-exhaustive list of possible terms.
A DPA may require the organisation to:
- pay a financial penalty;
- compensate victims;
- donate money to charity or another third party;
- disgorge profits;
- implement or improve a compliance programme;
- cooperate in an investigation concerning the alleged conduct;
- pay the prosecutor’s reasonable costs; and
- comply with other agreed conditions.
The financial penalty should be broadly comparable to the fine a court would have imposed following a guilty plea.
The Sentencing Council guideline for corporate offenders remains central to assessing culpability, harm, turnover and proportionality. Compensation, confiscation or disgorgement, fine and costs may interact. The headline penalty does not necessarily represent the organisation’s total financial exposure.
The agreement will also be accompanied by a statement of facts. Its content requires exceptional care because it may:
- describe the alleged wrongdoing publicly;
- affect civil claims and regulatory proceedings;
- identify or imply criticism of individuals;
- influence overseas authorities;
- shape reputational reporting; and
- become relevant if the DPA is breached.
Negotiating a statement of facts is not cosmetic drafting. It is part of the substantive resolution.
The DPA decision matrix
Boards should assess a potential DPA through several lenses.
| Issue | Strategic question |
|---|---|
| Evidential basis | What offence can properly be alleged against which entity, and what evidence supports or undermines it? |
| Public interest | Why would a DPA, prosecution or no criminal action best serve justice? |
| Cooperation | What has the organisation done beyond legal compulsion, and can it sustain that approach? |
| Individuals | Does the proposed corporate account fairly distinguish corporate responsibility from individual guilt? |
| Privilege | What is validly privileged, what facts can be provided, and would any waiver be informed and controlled? |
| Financial terms | How will penalty, disgorgement, compensation, costs and ability to pay interact? |
| Remediation | What has actually changed in governance, personnel, incentives, systems and testing? |
| Cross-border exposure | How will another authority treat the report, admissions, facts and financial settlement? |
| Collateral effects | What are the consequences for licences, procurement, financing, insurance, civil claims and reputation? |
| Deliverability | Can the organisation comply with every proposed obligation for the full DPA period? |
The organisation should not pursue a DPA merely because prosecution appears worse. It must understand the admissions, obligations and downstream effects attached to the agreement.
Remediation must be evidenced
Remediation is not the production of a revised policy after the event.
Investigators and the court may examine:
- whether responsible individuals remain in control;
- how incentives and targets contributed to the conduct;
- whether concerns were ignored or suppressed;
- whether the board received accurate information;
- whether reporting lines and escalation routes changed;
- whether third-party relationships were reviewed;
- whether affected transactions were stopped;
- whether victims were compensated;
- whether disciplinary decisions were independent;
- whether controls were tested;
- whether failures recurred; and
- whether the organisation can demonstrate sustained improvement.
Useful evidence may include:
- board and committee minutes;
- revised authority matrices;
- control-testing results;
- audit findings and closure evidence;
- training records and competence assessments;
- disciplinary outcomes;
- third-party due diligence;
- remuneration changes;
- monitoring data;
- exception reports;
- whistleblowing analysis; and
- independent assurance.
The question is not whether a new framework exists on paper. It is whether the conditions that enabled the suspected offence have genuinely changed.
Cross-border reporting
Serious corporate investigations frequently engage more than one jurisdiction.
The organisation may face:
- different notification thresholds;
- competing investigative priorities;
- legal restrictions on data transfer;
- blocking statutes;
- secrecy laws;
- different privilege rules;
- coordinated or successive settlements;
- currency and penalty-allocation questions;
- inconsistent approaches to individuals; and
- risks of double counting.
The SFO regards unreasonable forum shopping and attempts to exploit differences between enforcement agencies as uncooperative. Legitimate legal restrictions should be identified and explained.
A cross-border plan should map:
- every relevant jurisdiction;
- the conduct and entity connection to each;
- mandatory and voluntary reporting routes;
- preservation and transfer restrictions;
- privilege consequences;
- sequencing and coordination options;
- exposure of individuals;
- likely civil and regulatory consequences; and
- the proposed single factual chronology.
The chronology should be consistent, but reports need not be identical where legal duties and evidential thresholds differ. Any difference should have a defensible reason.
Communications and reputation
A self-report creates a communications problem, but communications should not control the legal investigation.
Statements to employees, markets, customers, auditors, insurers and the public can:
- create admissions;
- prejudice witnesses;
- disclose privileged strategy;
- misstate an incomplete investigation;
- trigger regulatory scrutiny;
- undermine later cooperation; or
- unfairly identify individuals.
The organisation should agree:
- who may speak;
- what facts are verified;
- what legal and regulatory disclosures are required;
- how uncertainty will be expressed;
- how affected individuals will be treated;
- when statements will be updated; and
- how consistency will be checked.
“We are investigating” should mean that a properly governed process exists. “We are cooperating” should not be used as a slogan if the organisation is resisting or delaying behind the scenes.
A seven-phase response protocol
Phase 1: preserve and stabilise
- stop continuing loss or offending;
- preserve digital and hard-copy material;
- secure volatile accounts, logs and devices;
- protect assets;
- prevent retaliation against reporters;
- record immediate decisions; and
- avoid premature witness discussions.
Phase 2: establish governance
- define the client and decision-maker;
- identify conflicts;
- establish privilege protocols;
- create an independent investigation structure;
- appoint reporting and communications leads; and
- set board oversight.
Phase 3: build the exposure and reporting map
- identify potential offences;
- map individuals, entities and jurisdictions;
- identify mandatory notifications;
- assess voluntary reporting routes;
- determine deadlines and triggers; and
- coordinate insurers, auditors and regulators.
Phase 4: conduct the minimum viable investigation
- verify the allegation;
- secure first-hand evidence;
- distinguish fact, suspicion, dispute and unknown;
- assess evidence and asset risks;
- identify urgent remediation; and
- produce a documented reporting recommendation.
Phase 5: make the controlled report
- identify known facts and suspected offences;
- name relevant people and entities accurately;
- explain jurisdictions and evidence locations;
- identify preservation and dissipation risks;
- state what remains unknown;
- agree digital-production format; and
- propose the next engagement.
Phase 6: cooperate without contaminating
- agree investigation parameters;
- coordinate interviews;
- provide organised material;
- explain restrictions promptly;
- update on findings and remediation;
- protect valid privilege;
- revisit conflicts; and
- preserve exculpatory as well as incriminating evidence.
Phase 7: assess and negotiate resolution
- test the evidential case;
- build the public-interest analysis;
- evaluate DPA eligibility;
- scrutinise the statement of facts;
- model financial and collateral consequences;
- evidence remediation;
- protect the proper position of individuals; and
- ensure every proposed term is deliverable.
Board questions
The board should be able to answer:
- What exactly do we know, and what remains allegation or inference?
- When did sufficiently credible evidence first come to light?
- What have we done to preserve evidence and prevent further harm?
- Which entity, individual, offence and jurisdiction may be involved?
- What notifications are mandatory, and what voluntary reports are under consideration?
- Who is making the decision, and are they independent of the suspected conduct?
- What is the legal basis and scope of privilege over the investigation?
- Could any proposed interview prejudice an external investigation or contaminate an account?
- Are we prepared to identify evidence and individuals pointing both towards and away from liability?
- What cooperation can we provide beyond legal compulsion?
- What remediation has operated in practice?
- What would a DPA require, and what consequences would remain after it?
If those questions cannot be answered, the organisation is not ready to treat reporting as a single communications decision.
Common strategic failures
Waiting for a complete investigation
The organisation spends months producing a polished report while evidence, witnesses or authorities move independently. A reasonable scoping exercise becomes tactical delay.
Reporting before preservation
The authority is notified, but disappearing messages, personal devices, cloud logs, third-party records or payment evidence have not been secured.
Treating allegation as admission
The first report collapses fact, suspicion and legal conclusion into one narrative which later proves inaccurate.
Treating one report as universal
A SAR, regulatory notice or overseas report is assumed to count as an SFO self-report when it does not.
Offering cooperation without governance
Different teams make inconsistent disclosures, interview witnesses independently and produce material without a defined factual or privilege review.
Using privilege tactically
Weak or blanket privilege claims undermine credibility. Conversely, premature waiver causes avoidable loss of protection.
Hiding the individuals
The organisation presents misconduct as a systems failure while obscuring who acted, decided and knew.
Sacrificing the individuals
The organisation adopts allegations against employees as fact to improve its corporate position without fair evidential analysis.
Mistaking volume for cooperation
Investigators receive an unstructured data dump which conceals rather than reveals what matters.
Treating remediation as policy revision
Documents change, but incentives, authority, people and actual practice do not.
Assuming a DPA is promised
The board plans around an invitation that remains prosecutorially discretionary, negotiable and subject to judicial approval.
Frequently asked questions
Must a company report suspected fraud to the SFO?
There is no general rule requiring every company to report every suspected fraud to the SFO. Specific regulatory, money-laundering, market, data-protection or contractual duties may nevertheless require notification. A voluntary SFO self-report may materially affect the prospect of a DPA and the public-interest assessment. The correct answer depends on the organisation, the conduct and the applicable reporting regimes.
How quickly must an organisation self-report?
The SFO expects reporting within a reasonable time and gives particular weight to promptness. It recognises that some investigation may be needed to understand an unclear allegation, but does not expect a full internal investigation before reporting. Direct evidence of corporate offending usually requires a faster decision than an unverified allegation.
Should the organisation investigate before contacting the SFO?
Usually it should conduct enough privileged work to preserve evidence, identify the apparent conduct, people, entities, jurisdictions and reporting obligations, and distinguish verified facts from suspicion. It should not delay solely to complete a comprehensive investigation or interview every witness.
Does making a Suspicious Activity Report count as an SFO self-report?
No. The SFO’s guidance states that a SAR or a report to another domestic or foreign agency is not an SFO self-report unless the suspected offending is also reported to the SFO simultaneously or immediately afterwards.
Does a prompt self-report guarantee a DPA?
No. The SFO states that prompt self-reporting and full cooperation will ordinarily result in an invitation to negotiate unless exceptional circumstances apply. The invitation is discretionary, negotiations may fail, and the court must approve any DPA as being in the interests of justice with fair, reasonable and proportionate terms.
Must an organisation waive privilege to cooperate?
No. The SFO says that maintaining a valid claim to legal professional privilege will not be penalised. It regards waiver as a significant cooperative act. Any waiver decision should be informed, limited where appropriate and assessed across criminal, regulatory, civil and cross-border consequences.
Can individuals receive a DPA?
No. The statutory DPA regime applies to organisations. Employees, directors and other individuals remain exposed to investigation and prosecution. A corporate DPA does not determine an individual’s guilt.
Is compliance with a section 2 notice cooperation?
Compliance is legally required and does not by itself amount to cooperation above and beyond the law. The SFO recognises that organisations may legitimately request a compulsory notice, including where legal authority is needed for production, and says that this request does not itself demonstrate a lack of cooperation.
What happens if an organisation breaches a DPA?
The prosecutor may apply to the Crown Court. If the court finds a breach on the balance of probabilities, it may invite the parties to agree proposals to remedy it or terminate the DPA. Termination may allow the suspended prosecution to continue.
Conclusion
The first reporting decision is rarely made with complete information. That does not justify paralysis, and it does not justify uncontrolled disclosure.
The organisation should preserve first, establish governance, identify mandatory duties, investigate only far enough to report responsibly and then cooperate through a process that remains accurate, fair and legally controlled.
A DPA may offer a powerful alternative to prosecution. It still carries public findings, substantial financial consequences, continuing obligations and risks for individuals. It depends on prosecutorial discretion, genuine cooperation and judicial approval.
The final principle is:
Report what is known, identify what is not, and never promise an outcome the evidence and the court have not yet decided.
Self-reporting is not a confession. It is a controlled disclosure of verified facts, known risks and the organisation's response.
Craig MacKenzie provides strategic advice through Forbes Solicitors to organisations, boards and senior leaders on evidence preservation, internal investigations, reporting obligations, SFO engagement, corporate and individual exposure, cooperation and potential DPA resolution.
Request a confidential consultationDo You Require Advice About Your Circumstances?
This material provides general information and is not a substitute for advice about a specific investigation or case.
Craig provides legal services exclusively through Forbes Solicitors. To make an initial enquiry, contact Craig at:
craig.mackenzie@forbessolicitors.co.uk
An enquiry does not constitute an instruction. Forbes Solicitors must confirm in writing that it has accepted the matter before any solicitor–client relationship arises.
Related Guidance
The First 24 Hours After Suspected Corporate Fraud
Guide 1 in this series: controlling harm, preserving evidence and making defensible decisions on day one.
Failure to Prevent Fraud: A Strategic Guide
Guide 2 in this series: corporate exposure, the reasonable procedures defence and the evidence boards should be able to produce.
Internal Investigations: Privilege, Interviews and Evidence Contamination
Guide 5 in this series: privilege, interview sequencing and preventing evidence contamination in internal investigations.
Corporate Criminal Liability: Senior Managers, Associated Persons and Failure to Prevent Fraud
Guide 6 in this series: mapping the routes to corporate liability and separating corporate exposure from individual guilt.
When an AI Failure Is Not Fraud but Still Creates Regulatory Exposure
Guide 8 in this series: identifying the regulatory, civil and professional routes when an AI failure is not fraud.
AI-Enabled Financial Crime and Corporate Investigations
The cornerstone guidance hub on how AI is changing fraud, corporate liability and investigations.