Our Expert in Finland
No results available
Corporate fraud investigation finland scenarios now sit at the top of the risk register for boards, general counsel and senior executives operating in the Finnish market. The current enforcement environment, shaped by corporate criminal liability under the Criminal Code and a continuing prosecutorial focus on accounting and financial offences, means a suspected fraud is not a matter that can be managed quietly and slowly. This guide sets out an actionable, procedural response: what to do in the first 72 hours, how to preserve evidence and confidentiality, when to notify authorities, and how to prepare for a criminal investigation (esitutkinta) in Finland. It is written for decision‑makers who need to act correctly and defensibly under pressure.
Who this guide is for: boards, general counsel, CEOs, CFOs and senior executives of Finnish and foreign companies operating in Finland.
What it delivers: step‑by‑step procedures, indicative timelines, required documents, planning‑level cost ranges, and the pitfalls to avoid when facing suspected accounting fraud or an official criminal investigation.
Disclaimer: This article provides general information and does not constitute legal advice. Contact a qualified Finnish lawyer for case‑specific advice.
A corporate fraud investigation finland matter typically begins with a signal, a whistleblower report, an auditor’s qualified finding, a bank query, or a police approach. From that moment, the company’s decisions determine whether it retains control of the facts, protects confidential legal advice, and positions itself credibly with prosecutors. This guide covers three overlapping tracks: suspected accounting fraud, the internal investigation the company should commission, and the concurrent criminal investigation that Finnish authorities may open.
It does not cover the detail of labour‑law dismissal procedure, cross‑border sanctions compliance, or tax‑audit mechanics, though each may intersect with a fraud matter and should be handled by specialist counsel in parallel.
The board sets the governance response: it constitutes a restricted committee, authorises spend, and oversees independence. The general counsel executes: retaining outside counsel, instructing IT preservation, and coordinating forensics. Where the CEO or CFO is a potential subject, the board must ensure the investigation is insulated from those individuals to protect its credibility.
This guide applies as soon as a credible trigger emerges. Do not wait for certainty; the need to preserve evidence and the strategic advantages of an early response both crystallise at the point of reasonable suspicion. Triggers that should prompt immediate action include:
The Criminal Code of Finland (rikoslaki, 39/1889) defines the core business offences most relevant here, including fraud, accounting offences (false or neglected bookkeeping), embezzlement, and bribery. Accounting fraud in Finland frequently overlaps with tax offences and abuse of position, so early legal classification of the suspected conduct shapes both the internal scope and the eventual defence.
The following ten steps present the disciplined sequence a board and general counsel should follow. Each identifies the responsible actor, the immediate action, and the strategic consideration. The timeline table below maps every step to who owns it and how long it typically takes. All durations are indicative and vary with complexity.
| Step # | Action | Who | Estimated duration |
|---|---|---|---|
| 1 | Convene board/emergency committee & appoint lead | Board / Chair / GC | 24–72 hours |
| 2 | Secure and preserve evidence (IT, accounting, backups) | IT, Forensics, Outside counsel | 24–72 hours initial; forensic imaging 3–7 days |
| 3 | Retain independent outside counsel & forensic specialists | GC / Board | 24–72 hours |
| 4 | Scope internal investigation & agree terms of reference | Outside counsel + investigators | 3–10 days |
| 5 | Conduct interviews & document findings | Outside counsel / investigators | 1–4 weeks |
| 6 | Assess reporting obligations & decide on self‑report | Outside counsel + GC | 3–14 days after initial findings |
| 7 | Engage authorities (if required) | Outside counsel / CEO | Initial contact within days of decision |
| 8 | Implement remediation & discipline | Management / HR / Board | 1–8 weeks |
| 9 | Prepare defence (if criminal charges) | Defence counsel | Pre‑trial readiness 2–6 months |
| 10 | Board report & governance reforms | Board / GC | 2–8 weeks post‑investigation |
Within 24 to 72 hours, the chair should constitute a restricted emergency committee, excluding any individual who may be a subject. Appoint an interim lead, usually the general counsel or a non‑executive director, to coordinate the response. Immediately retain independent outside counsel and instruct IT to secure systems for forensic capture. The single most damaging early error is broad internal circulation of the allegation, which contaminates witnesses and undermines the confidentiality of legal advice. Keep the initial factual record tight and channelled through counsel.
Evidence preservation is the highest‑priority technical task and must start in parallel with Step 1, not after it. Suspend automated deletion, preserve email and collaboration platform data (Teams, Slack), back up accounting systems, and freeze relevant user accounts without alerting subjects prematurely. Forensic imaging of key devices should be completed promptly, with cryptographic hashing and a documented chain of custody so that images remain reliable and admissible. Digital evidence preservation done poorly, or late, is frequently the difference between a defensible investigation and one that collapses under scrutiny.
Independence matters. Where the potential subjects are senior, using only in‑house counsel undermines credibility with the board, auditors and prosecutors. Retain independent outside counsel to lead, and instruct forensic accountants and digital forensic specialists under that counsel’s direction. This structure supports a coherent confidentiality strategy and ensures the fact‑finding is directed by legal advisers rather than by those with a stake in the outcome. Engagement letters should define scope, reporting lines and the confidentiality framework from the outset.
An internal fraud investigation should be governed by written terms of reference: the specific allegations, the custodians and systems in scope, the timeline, the reporting protocol, and the confidentiality regime. Resist over‑collection, gathering more than the allegations warrant increases cost, data‑privacy exposure, and the risk of surfacing collateral issues without a plan. Interviews should follow a documented plan, be conducted by counsel, and be recorded in memoranda held within the confidential legal workstream.
There is no blanket duty requiring a company to report every suspected offence to the police. However, once initial findings indicate a criminal offence, several considerations converge: sectoral reporting duties (notably for financial institutions supervised by the Financial Supervisory Authority), the risk to evidence, and the strategic value of cooperation. This decision, typically taken 3 to 14 days after initial findings, must be made with outside counsel and documented. The comparison table below sets out the practical trade‑offs.
Interview strategy is where legal risk concentrates. For internal interviews, employees have limited formal rights to counsel, but best practice is to permit counsel where an employee is a potential suspect or faces disciplinary consequences. Give appropriate warnings about the purpose of the interview and the fact that outside counsel represents the company, not the individual. For any subsequent police interview under esitutkinta, the rights of suspects and witnesses are materially stronger, and the individual’s own counsel should be involved.
If the police or a prosecutor makes contact, a single controlled channel, outside counsel, with the CEO briefed, should manage the interaction. Provide limited, considered disclosure rather than ad hoc document handovers. Where a search or seizure is anticipated, counsel can seek to agree protective measures and to identify and ring‑fence material subject to confidentiality before it is taken. Cooperation demonstrated early and correctly is one of the strongest mitigating signals available.
Remediation typically runs on a one‑to‑eight‑week horizon and may be considered by prosecutors and courts as evidence of good faith. Steps include suspension of implicated individuals pending findings, disciplinary action, restitution or recovery of misappropriated funds where possible, and correction of the control failures that allowed the conduct. Remediation is not an admission of corporate guilt; it is a demonstration that governance is functioning.
If charges follow, defence readiness depends on evidence preserved months earlier. Coordinate the criminal defence with any parallel civil claims, insurer notifications and regulatory processes so that positions taken in one forum do not undermine another. Maintain the confidential legal workstream separately from operational documents throughout.
Within two to eight weeks of concluding the investigation, the board should receive a formal report, adopt a remedial plan, and record decisions in properly framed minutes. For listed companies, coordinate any market disclosure and investor communications with legal and regulatory advice. The lasting value of a well‑run corporate fraud investigation finland process is a demonstrably stronger control environment.
Finnish law does not mirror common‑law legal professional privilege. Attorneys admitted to the Finnish Bar Association (asianajaja) are bound by professional secrecy obligations, and procedural rules protect certain confidential communications between a client and a legal adviser from disclosure and testimony. The treatment of internal fact‑finding material is more nuanced than executives from common‑law jurisdictions may expect, and protection generally attaches to legal advice rather than to underlying business records. Practical protections include directing the investigation through independent outside counsel who are members of the Bar, keeping legal advice clearly separable from raw fact collection, and maintaining a dedicated confidentiality log.
This framework should be settled before, not during, fact‑finding, with reference to the Finnish Bar Association’s rules and the applicable procedural legislation.
Internal investigations process personal data on a large scale, emails, HR files, access logs, bringing the GDPR and Finland’s Data Protection Act into play. Engage data‑privacy counsel or the data protection officer early to confirm lawful bases for processing, data minimisation, and rules on any transfer of data outside the EEA to foreign counsel or forensic vendors. Ignoring the data‑protection dimension of a corporate fraud investigation finland matter creates a second legal exposure alongside the fraud itself.
Communications should be minimal, accurate and centralised. Internally, restrict messaging to the need‑to‑know list. Externally, avoid speculative statements; a holding line coordinated with counsel is safer than detail. Listed companies must weigh disclosure obligations carefully, including under the EU Market Abuse Regulation, balancing market‑integrity duties against the risk of prejudicing an active investigation.
| Response option | Speed | Control over narrative | Risk of prosecution | Typical benefit |
|---|---|---|---|---|
| Internal investigation only | Moderate | High initially | Medium–High if not disclosed | Clarifies facts, preserves evidence |
| Self‑report to authorities (voluntary) | Fast | Low to moderate | Immediate exposure, potential mitigation | Possible cooperation credit at sentencing |
| Immediate engagement upon tip | Fastest | Low | Depends on cooperation | May reduce disruption; shows cooperation |
Documents should be collected in priority order, with financial records, electronic communications and system logs first, and all handling logged for chain of custody. The table sets out the categories, examples and evidential purpose.
| Document category | Examples / specifics | Why needed |
|---|---|---|
| Financial & accounting records | General ledger, trial balance, journal entries, bank statements, reconciliations, invoices | Primary evidence for accounting offences |
| Audit & assurance materials | External auditor communications, workpapers, management letters | Shows prior findings and control weaknesses |
| Electronic communications | Emails, Teams/Slack logs, instant messages, deleted‑item backups | Context and intent evidence |
| Transactional documentation | Contracts, purchase orders, approvals, expense claims | Supports or rebuts fraudulent transactions |
| Access & system logs | ERP logs, login records, file‑access timestamps | Establishes who accessed or changed records |
| HR & personnel files | Employment agreements, performance reviews, disciplinary files | Corroborates authority and context |
| Board & committee minutes | Board minutes, special committee resolutions | Demonstrates governance response |
| Forensic images & chain of custody | Disk images, hash values, evidence transfer records | Preserves admissibility |
| External correspondence | Regulator notices, whistleblower reports, third‑party complaints | Triggers and external inputs |
| Legal & confidential materials | Engagement letters, confidentiality logs (held separately) | Supports defence and confidentiality claims |
Two clocks run in parallel: the company’s internal timeline, which it controls, and the criminal process, which it does not. Internally, preservation should happen within 24 to 72 hours, scoping and retention of specialists within 3 to 10 days, and the internal inquiry itself over 1 to 8 weeks depending on complexity. The reporting decision typically follows within one to three weeks of initial findings.
The criminal process is governed by the Criminal Investigation Act (esitutkintalaki, 805/2011) and the Coercive Measures Act (pakkokeinolaki, 806/2011). A police preliminary investigation (esitutkinta) can run from several weeks to many months, and complex or cross‑border corporate matters commonly extend well beyond that. Police search and seizure powers are exercised within statutory limits, and a prosecutor’s charging decision follows once the investigation file is complete. Limitation periods apply to the underlying offences under the Criminal Code and vary by offence and applicable penalty, so early legal classification matters. The table summarises typical phases.
| Phase | Typical timeframe (indicative) | Often controlled by |
|---|---|---|
| Initial response & preservation | 24–72 hours | Company (GC/IT/Forensics) |
| Scoping & retention of specialists | 3–10 days | Company |
| Internal investigation | 1–8 weeks | Outside counsel / investigators |
| Decision on reporting / self‑report | 1–3 weeks after findings | Company + counsel |
| Police preliminary investigation (esitutkinta) | Several weeks to many months | Police / Prosecutor |
| Prosecutor charging decision | Weeks to months after evidence | Prosecutor |
| Trial / settlement | Months to years | Courts / parties |
Costs are driven by the number of custodians, the volume of data, the complexity of the accounting issues, and the seniority of counsel. The ranges below are illustrative planning figures for the Finnish market only, not quotations, and actual fees should be confirmed with each provider.
| Cost item | Indicative range (planning only) | Notes |
|---|---|---|
| Immediate outside counsel (initial retention) | Varies by firm and scope | Confirm with the firm engaged |
| Forensic imaging & triage (per matter) | Varies by devices and cloud systems | Obtain a scoped quote |
| Full forensic review (per custodian) | Varies by data volume | Priced per custodian/data set |
| Ongoing outside counsel (hourly) | At prevailing market rates; senior partners at the high end | Confirm current hourly rates |
| Expert / accounting review | Rises with accounting complexity | Complex fraud increases cost |
| Regulatory fines / penalties | Varies by offence | Depends on offence and remediation |
| Employee disciplinary actions | Variable | HR/legal costs, potential severance |
| Compliance remediation programme | Variable | Training, systems, monitoring |
Finnish law provides for corporate criminal liability (oikeushenkilön rangaistusvastuu) under Chapter 9 of the Criminal Code, under which a legal person can be sentenced to a corporate fine for certain offences committed in its operations, including many economic offences. The practical consequences for boards are direct: prosecutors may pursue a corporate fine against the company itself, not only individuals; corporate governance and internal controls can be a live issue in charging and sentencing; and remedial conduct is relevant to how a matter is assessed. Companies should follow the Ministry of Justice and Finlex legislative materials for the precise current texts, and treat prosecutor guidance as a signal of enforcement priorities.
A corporate fraud investigation finland matter tests governance under pressure. Boards that preserve evidence within hours, retain independent counsel before fact‑finding, plan confidentiality deliberately, and make the reporting decision on advice will protect both the company and themselves. Treat this guide as a preparedness framework, and put counsel and forensic relationships in place before the first allegation arrives, not after.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Annastiina Latvasaho at Salingre Attorneys, a member of the Global Law Experts network.
posted 4 minutes ago
posted 6 minutes ago
posted 9 minutes ago
posted 12 minutes ago
posted 12 minutes ago
posted 15 minutes ago
posted 17 minutes ago
posted 20 minutes ago
posted 22 minutes ago
posted 26 minutes ago
posted 32 minutes ago
posted 37 minutes ago
No results available
Find the right Legal Expert for your business
Send welcome message