[codicts-css-switcher id=”346″]

Global Law Experts Logo
corporate fraud investigation finland

How to Respond to a Corporate Fraud Investigation in Finland (2026), Step‑by‑step Guide for Boards & Executives

By Global Law Experts
– posted 1 hour ago

Corporate fraud investigation finland scenarios now sit at the top of the risk register for boards, general counsel and senior executives operating in the Finnish market. The current enforcement environment, shaped by corporate criminal liability under the Criminal Code and a continuing prosecutorial focus on accounting and financial offences, means a suspected fraud is not a matter that can be managed quietly and slowly. This guide sets out an actionable, procedural response: what to do in the first 72 hours, how to preserve evidence and confidentiality, when to notify authorities, and how to prepare for a criminal investigation (esitutkinta) in Finland. It is written for decision‑makers who need to act correctly and defensibly under pressure.

Who this guide is for: boards, general counsel, CEOs, CFOs and senior executives of Finnish and foreign companies operating in Finland.

What it delivers: step‑by‑step procedures, indicative timelines, required documents, planning‑level cost ranges, and the pitfalls to avoid when facing suspected accounting fraud or an official criminal investigation.

Disclaimer: This article provides general information and does not constitute legal advice. Contact a qualified Finnish lawyer for case‑specific advice.

Introduction and overview

A corporate fraud investigation finland matter typically begins with a signal, a whistleblower report, an auditor’s qualified finding, a bank query, or a police approach. From that moment, the company’s decisions determine whether it retains control of the facts, protects confidential legal advice, and positions itself credibly with prosecutors. This guide covers three overlapping tracks: suspected accounting fraud, the internal investigation the company should commission, and the concurrent criminal investigation that Finnish authorities may open.

It does not cover the detail of labour‑law dismissal procedure, cross‑border sanctions compliance, or tax‑audit mechanics, though each may intersect with a fraud matter and should be handled by specialist counsel in parallel.

When to use this guide (board vs GC actions)

The board sets the governance response: it constitutes a restricted committee, authorises spend, and oversees independence. The general counsel executes: retaining outside counsel, instructing IT preservation, and coordinating forensics. Where the CEO or CFO is a potential subject, the board must ensure the investigation is insulated from those individuals to protect its credibility.

Quick checklist

  • Restrict. Limit knowledge of the allegation to a strict need‑to‑know list.
  • Preserve. Instruct IT and finance to suspend deletion and preserve records immediately.
  • Retain. Engage independent outside counsel before internal fact‑finding begins.
  • Assess. Do not decide on self‑reporting until initial findings are in and legally reviewed.
  • Document. Record every decision in properly minuted form.

Eligibility: when this applies

This guide applies as soon as a credible trigger emerges. Do not wait for certainty; the need to preserve evidence and the strategic advantages of an early response both crystallise at the point of reasonable suspicion. Triggers that should prompt immediate action include:

  • Whistleblower reports through internal channels or external disclosure lines.
  • External auditor red flags, qualified opinions, management letters, or unexplained reconciliation gaps.
  • Police approach or a request for documents by investigators.
  • Regulator notice, including from the Financial Supervisory Authority (Finanssivalvonta) for regulated entities.
  • Suspicious transactions, round‑sum payments, unfamiliar counterparties, or circumvented approval controls.
  • Insolvency indicators, where creditor scrutiny commonly surfaces accounting irregularities.

Types of suspected offence covered

The Criminal Code of Finland (rikoslaki, 39/1889) defines the core business offences most relevant here, including fraud, accounting offences (false or neglected bookkeeping), embezzlement, and bribery. Accounting fraud in Finland frequently overlaps with tax offences and abuse of position, so early legal classification of the suspected conduct shapes both the internal scope and the eventual defence.

Step‑by‑step response to a corporate fraud investigation in Finland

The following ten steps present the disciplined sequence a board and general counsel should follow. Each identifies the responsible actor, the immediate action, and the strategic consideration. The timeline table below maps every step to who owns it and how long it typically takes. All durations are indicative and vary with complexity.

Step # Action Who Estimated duration
1 Convene board/emergency committee & appoint lead Board / Chair / GC 24–72 hours
2 Secure and preserve evidence (IT, accounting, backups) IT, Forensics, Outside counsel 24–72 hours initial; forensic imaging 3–7 days
3 Retain independent outside counsel & forensic specialists GC / Board 24–72 hours
4 Scope internal investigation & agree terms of reference Outside counsel + investigators 3–10 days
5 Conduct interviews & document findings Outside counsel / investigators 1–4 weeks
6 Assess reporting obligations & decide on self‑report Outside counsel + GC 3–14 days after initial findings
7 Engage authorities (if required) Outside counsel / CEO Initial contact within days of decision
8 Implement remediation & discipline Management / HR / Board 1–8 weeks
9 Prepare defence (if criminal charges) Defence counsel Pre‑trial readiness 2–6 months
10 Board report & governance reforms Board / GC 2–8 weeks post‑investigation

Step 1, Convene the board or an emergency committee

Within 24 to 72 hours, the chair should constitute a restricted emergency committee, excluding any individual who may be a subject. Appoint an interim lead, usually the general counsel or a non‑executive director, to coordinate the response. Immediately retain independent outside counsel and instruct IT to secure systems for forensic capture. The single most damaging early error is broad internal circulation of the allegation, which contaminates witnesses and undermines the confidentiality of legal advice. Keep the initial factual record tight and channelled through counsel.

Step 2, Secure and preserve evidence

Evidence preservation is the highest‑priority technical task and must start in parallel with Step 1, not after it. Suspend automated deletion, preserve email and collaboration platform data (Teams, Slack), back up accounting systems, and freeze relevant user accounts without alerting subjects prematurely. Forensic imaging of key devices should be completed promptly, with cryptographic hashing and a documented chain of custody so that images remain reliable and admissible. Digital evidence preservation done poorly, or late, is frequently the difference between a defensible investigation and one that collapses under scrutiny.

Step 3, Engage independent outside counsel and forensic specialists

Independence matters. Where the potential subjects are senior, using only in‑house counsel undermines credibility with the board, auditors and prosecutors. Retain independent outside counsel to lead, and instruct forensic accountants and digital forensic specialists under that counsel’s direction. This structure supports a coherent confidentiality strategy and ensures the fact‑finding is directed by legal advisers rather than by those with a stake in the outcome. Engagement letters should define scope, reporting lines and the confidentiality framework from the outset.

Step 4, Scope and run a narrow internal fraud investigation

An internal fraud investigation should be governed by written terms of reference: the specific allegations, the custodians and systems in scope, the timeline, the reporting protocol, and the confidentiality regime. Resist over‑collection, gathering more than the allegations warrant increases cost, data‑privacy exposure, and the risk of surfacing collateral issues without a plan. Interviews should follow a documented plan, be conducted by counsel, and be recorded in memoranda held within the confidential legal workstream.

Step 5, Assess reporting obligations and decide on self‑reporting

There is no blanket duty requiring a company to report every suspected offence to the police. However, once initial findings indicate a criminal offence, several considerations converge: sectoral reporting duties (notably for financial institutions supervised by the Financial Supervisory Authority), the risk to evidence, and the strategic value of cooperation. This decision, typically taken 3 to 14 days after initial findings, must be made with outside counsel and documented. The comparison table below sets out the practical trade‑offs.

Step 6, Prepare for executive interviews and access rights

Interview strategy is where legal risk concentrates. For internal interviews, employees have limited formal rights to counsel, but best practice is to permit counsel where an employee is a potential suspect or faces disciplinary consequences. Give appropriate warnings about the purpose of the interview and the fact that outside counsel represents the company, not the individual. For any subsequent police interview under esitutkinta, the rights of suspects and witnesses are materially stronger, and the individual’s own counsel should be involved.

Step 7, Engage with authorities if approached

If the police or a prosecutor makes contact, a single controlled channel, outside counsel, with the CEO briefed, should manage the interaction. Provide limited, considered disclosure rather than ad hoc document handovers. Where a search or seizure is anticipated, counsel can seek to agree protective measures and to identify and ring‑fence material subject to confidentiality before it is taken. Cooperation demonstrated early and correctly is one of the strongest mitigating signals available.

Step 8, Mitigation and remediation

Remediation typically runs on a one‑to‑eight‑week horizon and may be considered by prosecutors and courts as evidence of good faith. Steps include suspension of implicated individuals pending findings, disciplinary action, restitution or recovery of misappropriated funds where possible, and correction of the control failures that allowed the conduct. Remediation is not an admission of corporate guilt; it is a demonstration that governance is functioning.

Step 9, Litigation and defence readiness

If charges follow, defence readiness depends on evidence preserved months earlier. Coordinate the criminal defence with any parallel civil claims, insurer notifications and regulatory processes so that positions taken in one forum do not undermine another. Maintain the confidential legal workstream separately from operational documents throughout.

Step 10, Board reporting and post‑investigation governance

Within two to eight weeks of concluding the investigation, the board should receive a formal report, adopt a remedial plan, and record decisions in properly framed minutes. For listed companies, coordinate any market disclosure and investor communications with legal and regulatory advice. The lasting value of a well‑run corporate fraud investigation finland process is a demonstrably stronger control environment.

Confidentiality and legal advice protection in Finland

Finnish law does not mirror common‑law legal professional privilege. Attorneys admitted to the Finnish Bar Association (asianajaja) are bound by professional secrecy obligations, and procedural rules protect certain confidential communications between a client and a legal adviser from disclosure and testimony. The treatment of internal fact‑finding material is more nuanced than executives from common‑law jurisdictions may expect, and protection generally attaches to legal advice rather than to underlying business records. Practical protections include directing the investigation through independent outside counsel who are members of the Bar, keeping legal advice clearly separable from raw fact collection, and maintaining a dedicated confidentiality log.

This framework should be settled before, not during, fact‑finding, with reference to the Finnish Bar Association’s rules and the applicable procedural legislation.

Handling cross‑border data and GDPR considerations

Internal investigations process personal data on a large scale, emails, HR files, access logs, bringing the GDPR and Finland’s Data Protection Act into play. Engage data‑privacy counsel or the data protection officer early to confirm lawful bases for processing, data minimisation, and rules on any transfer of data outside the EEA to foreign counsel or forensic vendors. Ignoring the data‑protection dimension of a corporate fraud investigation finland matter creates a second legal exposure alongside the fraud itself.

Managing communications, internal and external

Communications should be minimal, accurate and centralised. Internally, restrict messaging to the need‑to‑know list. Externally, avoid speculative statements; a holding line coordinated with counsel is safer than detail. Listed companies must weigh disclosure obligations carefully, including under the EU Market Abuse Regulation, balancing market‑integrity duties against the risk of prejudicing an active investigation.

Comparing response options for a corporate fraud investigation in Finland

Response option Speed Control over narrative Risk of prosecution Typical benefit
Internal investigation only Moderate High initially Medium–High if not disclosed Clarifies facts, preserves evidence
Self‑report to authorities (voluntary) Fast Low to moderate Immediate exposure, potential mitigation Possible cooperation credit at sentencing
Immediate engagement upon tip Fastest Low Depends on cooperation May reduce disruption; shows cooperation

Required documents to gather promptly

Documents should be collected in priority order, with financial records, electronic communications and system logs first, and all handling logged for chain of custody. The table sets out the categories, examples and evidential purpose.

Document category Examples / specifics Why needed
Financial & accounting records General ledger, trial balance, journal entries, bank statements, reconciliations, invoices Primary evidence for accounting offences
Audit & assurance materials External auditor communications, workpapers, management letters Shows prior findings and control weaknesses
Electronic communications Emails, Teams/Slack logs, instant messages, deleted‑item backups Context and intent evidence
Transactional documentation Contracts, purchase orders, approvals, expense claims Supports or rebuts fraudulent transactions
Access & system logs ERP logs, login records, file‑access timestamps Establishes who accessed or changed records
HR & personnel files Employment agreements, performance reviews, disciplinary files Corroborates authority and context
Board & committee minutes Board minutes, special committee resolutions Demonstrates governance response
Forensic images & chain of custody Disk images, hash values, evidence transfer records Preserves admissibility
External correspondence Regulator notices, whistleblower reports, third‑party complaints Triggers and external inputs
Legal & confidential materials Engagement letters, confidentiality logs (held separately) Supports defence and confidentiality claims

Timeline and deadlines

Two clocks run in parallel: the company’s internal timeline, which it controls, and the criminal process, which it does not. Internally, preservation should happen within 24 to 72 hours, scoping and retention of specialists within 3 to 10 days, and the internal inquiry itself over 1 to 8 weeks depending on complexity. The reporting decision typically follows within one to three weeks of initial findings.

The criminal process is governed by the Criminal Investigation Act (esitutkintalaki, 805/2011) and the Coercive Measures Act (pakkokeinolaki, 806/2011). A police preliminary investigation (esitutkinta) can run from several weeks to many months, and complex or cross‑border corporate matters commonly extend well beyond that. Police search and seizure powers are exercised within statutory limits, and a prosecutor’s charging decision follows once the investigation file is complete. Limitation periods apply to the underlying offences under the Criminal Code and vary by offence and applicable penalty, so early legal classification matters. The table summarises typical phases.

Phase Typical timeframe (indicative) Often controlled by
Initial response & preservation 24–72 hours Company (GC/IT/Forensics)
Scoping & retention of specialists 3–10 days Company
Internal investigation 1–8 weeks Outside counsel / investigators
Decision on reporting / self‑report 1–3 weeks after findings Company + counsel
Police preliminary investigation (esitutkinta) Several weeks to many months Police / Prosecutor
Prosecutor charging decision Weeks to months after evidence Prosecutor
Trial / settlement Months to years Courts / parties

Costs and fees

Costs are driven by the number of custodians, the volume of data, the complexity of the accounting issues, and the seniority of counsel. The ranges below are illustrative planning figures for the Finnish market only, not quotations, and actual fees should be confirmed with each provider.

Cost item Indicative range (planning only) Notes
Immediate outside counsel (initial retention) Varies by firm and scope Confirm with the firm engaged
Forensic imaging & triage (per matter) Varies by devices and cloud systems Obtain a scoped quote
Full forensic review (per custodian) Varies by data volume Priced per custodian/data set
Ongoing outside counsel (hourly) At prevailing market rates; senior partners at the high end Confirm current hourly rates
Expert / accounting review Rises with accounting complexity Complex fraud increases cost
Regulatory fines / penalties Varies by offence Depends on offence and remediation
Employee disciplinary actions Variable HR/legal costs, potential severance
Compliance remediation programme Variable Training, systems, monitoring

Corporate criminal liability and enforcement focus in Finland

Finnish law provides for corporate criminal liability (oikeushenkilön rangaistusvastuu) under Chapter 9 of the Criminal Code, under which a legal person can be sentenced to a corporate fine for certain offences committed in its operations, including many economic offences. The practical consequences for boards are direct: prosecutors may pursue a corporate fine against the company itself, not only individuals; corporate governance and internal controls can be a live issue in charging and sentencing; and remedial conduct is relevant to how a matter is assessed. Companies should follow the Ministry of Justice and Finlex legislative materials for the precise current texts, and treat prosecutor guidance as a signal of enforcement priorities.

Immediate steps boards should take

  • Tighten oversight. Ensure audit and risk committees actively test controls rather than receiving assurance passively.
  • Pre‑arrange preservation. Have IT preservation and forensic capture protocols ready to deploy within hours.
  • Pre‑pack counsel relationships. Identify independent outside counsel and forensic vendors in advance so retention is not delayed at the critical moment.

Common pitfalls and how to avoid them

  • Over‑sharing internally. Broad circulation contaminates witnesses, restrict to a documented need‑to‑know list.
  • Delayed evidence preservation. Automated deletion destroys evidence, suspend it and image key devices immediately.
  • Ignoring GDPR. Investigations process personal data, involve data‑privacy counsel from the outset.
  • Weak confidentiality planning. Mixing advice and fact‑finding weakens protection, separate the workstreams and log confidential legal advice.
  • Relying only on in‑house counsel. Independence is doubted where subjects are senior, retain independent outside counsel who are members of the Bar.
  • Failing to document decisions. Undocumented choices look evasive later, minute every material decision contemporaneously.

Conclusion

A corporate fraud investigation finland matter tests governance under pressure. Boards that preserve evidence within hours, retain independent counsel before fact‑finding, plan confidentiality deliberately, and make the reporting decision on advice will protect both the company and themselves. Treat this guide as a preparedness framework, and put counsel and forensic relationships in place before the first allegation arrives, not after.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Annastiina Latvasaho at Salingre Attorneys, a member of the Global Law Experts network.

Sources

  1. Finlex, Criminal Code of Finland (Rikoslaki 39/1889)
  2. Finlex, Criminal Investigation Act (esitutkintalaki 805/2011)
  3. Finlex, Coercive Measures Act (pakkokeinolaki 806/2011)
  4. Ministry of Justice, Finland
  5. Police of Finland (Poliisi)
  6. Finnish Bar Association (Suomen Asianajajaliitto)
  7. Courts of Finland
  8. Financial Supervisory Authority (Finanssivalvonta)
  9. OECD, Anti‑Bribery Convention
  10. United Nations Office on Drugs and Crime, UNCAC

FAQs

When must a company in Finland notify the police about suspected accounting fraud?
There is no automatic rule requiring notification in every case. However, where initial findings indicate a criminal offence or an ongoing risk to evidence, the company should consult outside counsel promptly to decide on reporting. Certain regulated sectors carry statutory reporting duties, so check sector‑specific rules and consult Finlex and prosecutor guidance.
Protection generally attaches to confidential legal advice between a client and an attorney bound by professional secrecy, rather than to underlying business records. Finnish concepts differ from common‑law privilege and require careful separation of legal advice from raw fact‑finding. Use independent outside counsel who are members of the Finnish Bar Association and maintain a clear confidentiality log to strengthen any claim.
Employees have limited formal rights to counsel during purely internal interviews. For police interviews under esitutkinta, the rights of suspects and witnesses are stronger. Best practice is to permit counsel where an employee is a potential suspect or where disciplinary consequences are possible, coordinated with outside counsel.
Timing varies widely, from weeks to many months depending on complexity. Serious cross‑border or corporate matters commonly extend longer. Early cooperation and disciplined evidence preservation can shorten individual stages.
Self‑reporting and cooperation can operate as mitigating factors but do not guarantee immunity. Prosecutors and courts weigh the nature of the offence, the remedial measures taken, and the timeliness of reporting.
Companies may engage foreign counsel for advice, but representation before Finnish courts and in formal interactions typically requires local counsel or co‑counsel familiar with Finnish procedure. Check the applicable admission rules with the Finnish Bar Association and coordinate with local counsel.
Convene a restricted emergency committee, engage independent outside counsel, instruct IT to preserve systems, and limit dissemination of the allegation to a strict need‑to‑know list.
foreign law firms india
By Global Law Experts

posted 26 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Respond to a Corporate Fraud Investigation in Finland (2026), Step‑by‑step Guide for Boards & Executives

Send welcome message

Custom Message