Supply-chain fraud is rarely one single offence or one single weak control. It can involve dishonest suppliers, employees, intermediaries, subcontractors or criminals impersonating genuine businesses. The investigation therefore has to reconstruct the commercial process: who approved the supplier, who changed the bank details, who received the goods, what was invoiced, what was paid and what evidence exists at each stage.

At Trojan Investigations, we support organisations through business investigations involving suspected procurement fraud, stock theft, supplier deception, employee collusion and related misconduct. Our role is to establish facts, preserve evidence and help the client decide what should happen next.

Originally published: 14th July 2026  |  Updated: 7th September 2026

How should a business investigate suspected supply-chain fraud?

Preserve the records first, control further loss without alerting suspects unnecessarily, build a chronology of procurement and payment decisions, compare invoices to contracts and delivery evidence, identify who had authority at each stage, verify suppliers independently and escalate to legal, regulatory or police channels where the evidence requires it.

Supply-Chain Fraud Is Broader Than Fake Invoices

A supply chain may be attacked at tendering, onboarding, ordering, transport, warehousing, invoicing, payment or contract management. Fraud can be external — for example a fake supplier payment request — or internal, such as an employee creating a connected company and steering orders towards it.

Common supply-chain fraud patterns
Fraud patternTypical mechanismEvidence to preserve
Supplier impersonationCriminal changes bank details or impersonates an existing supplierOriginal emails, headers, payment-change requests, call logs and bank records
Procurement collusionEmployee and supplier manipulate quotations, orders or pricingTender files, approvals, messaging, pricing history and relationship links
Ghost supplierPayments made to an entity that does not provide genuine goods or servicesOnboarding documents, bank details, invoices, delivery evidence and ownership information
Invoice inflation or duplicationCharges exceed contract terms or the same item is paid more than onceContracts, purchase orders, invoice register and payment ledger
Stock diversionGoods are removed, substituted or diverted before reaching the intended destinationWarehouse records, CCTV, manifests, vehicle logs and stock counts
Counterfeit or substituted goodsLower-grade or fake products are supplied as genuineBatch numbers, specification records, samples, inspection results and supplier chain

Start by Containing Loss Without Destroying Evidence

Once fraud is suspected, there is often pressure to suspend staff, contact suppliers or change systems immediately. Some controls may be necessary to prevent further loss, but poorly planned action can delete logs, overwrite CCTV, trigger document destruction or alert people who are coordinating their accounts.

Immediate preservation priorities may include:

  • Purchase orders, approvals, tender documents and supplier onboarding records.
  • Invoice registers, payment instructions and bank-detail change requests.
  • Email and collaboration-platform material retained through the organisation's lawful IT processes.
  • Access logs, audit trails and user-account records.
  • Warehouse, delivery, vehicle and stock-control records.
  • CCTV footage before routine retention periods overwrite it.
  • Contracts, specifications, quality reports and goods-received notes.

Supplier Verification Should Go Beyond a Name Match

A company can exist legally and still present fraud risk. Verification may include ownership and control, directors, trading history, address credibility, sanctions exposure, insolvency indicators, litigation or regulatory history where lawfully available, and whether the supplier appears capable of delivering the goods or services being purchased.

HMRC supply-chain guidance uses a useful “check, act and review” approach: test the credibility and legitimacy of suppliers and transactions, act on warning signs, then keep the risk under review rather than treating onboarding as a one-off exercise.

Procurement Collusion Often Hides in the Approval Process

Employee collusion can involve kickbacks, tailored tender specifications, fake competition, confidential bid information, unexplained single-source awards, repeated emergency purchasing or approval splitting designed to stay below financial limits.

The investigation should map who initiated, approved and benefited from each decision. Personal relationships are relevant only where they connect to a business decision; the goal is not to investigate employees' private lives generally.

Public Procurement Has a Specific 2025–2026 Legal Framework

For covered public procurement in England, Wales and Northern Ireland, the Procurement Act 2023 regime came into force on 24 February 2025. Current Cabinet Office guidance, updated in August 2026, requires authorities to consider mandatory and discretionary exclusion grounds and the risks presented by suppliers, connected persons and certain associated persons.

Bid Rigging and Cartel Behaviour Need Specialist Escalation

Suspiciously coordinated bids, cover pricing, market sharing or suppliers taking turns to win work can indicate competition-law concerns. The Competition and Markets Authority has emphasised that the Procurement Act strengthened consequences for cartel activity in public procurement, including exclusion and potential debarment.

Where evidence points to anti-competitive behaviour rather than ordinary internal fraud, legal advice and appropriate reporting to the CMA may be required. A private investigation can help organise factual material, but it does not replace regulator powers.

Invoice Diversion Often Begins as Social Engineering

A supplier's email account may be compromised, or a criminal may use a lookalike domain and convincing signature block to request a bank-detail change. The safest control is independent verification using a known contact route, not replying to the message that requested the change.

When an incident has already happened, preserve the original message, headers, telephone numbers, bank details, payment authorisation history and the timeline of every internal decision. Contacting the bank quickly may also matter to any recovery attempt.

Stock, Cargo and Warehouse Fraud Need Physical Evidence

Inventory discrepancies can arise from genuine errors, poor systems or theft. Investigators compare stock records with goods-in/goods-out data, delivery documentation, access records, CCTV and vehicle movement. Patterns such as repeated shortages on one route or during one shift can narrow the enquiry without assuming guilt.

Where there is a defined activity to observe, lawful surveillance may help establish public movements, meetings or unauthorised removal of goods. It should be targeted and proportionate.

Counterfeit Goods Require Provenance, Not Just Suspicion

Suspected counterfeits should be preserved with packaging, batch identifiers, serial numbers, purchase records and a clear chain of custody. Technical comparison may require the manufacturer, rights holder or an appropriate expert.

A supplier's reluctance to provide provenance documents can be a warning sign, but the investigation should still distinguish poor administration from deliberate fraud.

Employee Data and Monitoring Must Be Handled Lawfully

Internal fraud investigations may involve staff emails, access logs, CCTV or other personal data. Employers remain responsible for data-protection compliance. Monitoring should have a defined purpose, lawful basis and proportionate scope, with access restricted to people who need the material for the investigation.

If a fraud incident also exposes personal data, the organisation may need to assess whether it is a reportable personal-data breach. That regulatory assessment should run in parallel with the fraud investigation rather than being overlooked because the main concern is financial loss.

Failure to Prevent Fraud May Matter to Larger Organisations

The Economic Crime and Corporate Transparency Act 2023 created a corporate offence of failure to prevent fraud for qualifying large organisations. The offence came into effect on 1 September 2025. Government guidance emphasises reasonable fraud-prevention procedures and a risk-based approach.

Not every supply-chain fraud triggers that offence, but the framework reinforces a broader governance point: organisations should understand how employees, agents and other associated persons could commit fraud for the organisation's benefit and design controls around those risks.

How We Structure a Supply-Chain Fraud Investigation

1. Define the suspected loss and period

We identify the transactions, products, suppliers or sites genuinely in question.

2. Preserve the original commercial records

Documents, logs, communications and CCTV are secured before routine deletion or informal editing changes the evidence.

3. Map people, approvals and money

We reconstruct who requested, approved, changed, delivered and received each relevant transaction.

4. Verify suppliers and relationships

Ownership, directorships, addresses and other public connections are checked where they are relevant to the suspected scheme.

5. Test alternative explanations

Control failures, error and poor administration are considered alongside deliberate fraud so the conclusion is evidence-led.

6. Report facts for the next decision

The final report separates verified findings from inference and identifies evidential gaps that may need legal, forensic or police powers.

Red Flags That Deserve Investigation

Payment changesNew bank details, urgent transfers or pressure to bypass normal verification.
Supplier concentrationOne employee repeatedly steering work to the same supplier without clear commercial reason.
Document mismatchInvoices, delivery notes, quantities or specifications that do not reconcile.
Unexplained stock lossRepeated shortages concentrated around particular routes, shifts or sites.

Red flags justify enquiry; they do not prove fraud. A well-run investigation should be capable of clearing innocent explanations as well as substantiating misconduct.

When to Involve Solicitors, Regulators or Police

If the suspected fraud is serious, ongoing, cross-border, connected to bribery or cartel conduct, or likely to result in litigation, early legal advice can protect privilege and shape evidence preservation. Criminal allegations may need to be reported to the police or the national fraud-reporting service, while competition concerns may fall within the CMA's remit.

Our legal and litigation support can be coordinated with the client's solicitors so the investigation produces material suitable for the decisions that follow.

Third-Party Access Can Be the Hidden Weak Point

Suppliers and contractors may have legitimate access to portals, stock systems, shared mailboxes, customer data or operational sites. Fraud risk increases when those permissions remain active after a contract changes, when subcontractors are not visible to the client or when several organisations share one generic account.

During an investigation, access rights should be mapped alongside financial approvals. Who could create or amend a supplier? Who could change bank details? Who could approve a goods-received note? Who could enter a warehouse or view delivery schedules? A fraud scheme often depends on combining two permissions that were never intended to sit together.

Conflicts of Interest Need Evidence, Not Assumptions

A personal connection between an employee and a supplier may be relevant, but it is not automatically fraudulent. The key question is whether the relationship affected a business decision or was concealed where disclosure was required.

Useful evidence can include company ownership, directorships, shared addresses, tender scoring, approval records, pricing history and communications that connect the relationship to the procurement decision. This is stronger than simply showing that two people know each other.

Interviews Should Follow the Documentary Evidence

Interviewing too early can allow suspects to tailor explanations around the questions being asked. Where possible, review the records first so the interviewer understands the chronology and can put specific discrepancies fairly to the person involved.

Witnesses should be asked open questions about the process they followed, what they knew at the time and which documents they relied on. The objective is to test the evidence, not to force a confession. HR and legal advisers should be involved where disciplinary rights or employment procedures are engaged.

Cross-Border Supply Chains Add Jurisdictional Limits

Overseas suppliers may involve different company registers, privacy laws, languages, banking systems and enforcement options. A UK investigator cannot assume that a method available domestically is lawful or effective abroad. Cross-border work should be planned around local legal advice and reliable in-country sources where necessary.

The same principle applies to recovery. Establishing that a payment or shipment went overseas does not by itself create a practical route to recover it. Early bank contact, insurer notification, legal advice and law-enforcement reporting may be more important than further private enquiry once the destination is known.

Contractual and Insurance Notifications Can Be Time-Critical

Fraud incidents may trigger contractual notice obligations, cyber or crime-insurance conditions, bank reporting requirements or duties to inform customers and regulators. Those deadlines can exist independently of the investigation. The organisation should therefore involve its legal, insurance, finance and data-protection contacts early rather than waiting for a final investigator's report.

The investigator's role is to preserve and organise the factual record so those advisers can make informed decisions. A clear chronology of discovery, containment, notifications and evidence handling can also help demonstrate that the business responded promptly.

Remediation Should Address the Route, Not Just the Individual

If the investigation substantiates fraud, removing one employee or supplier may not solve the control weakness that made the scheme possible. Review supplier onboarding, approval limits, conflicts declarations, payment-change verification, access rights, stock controls and audit logging.

The strongest outcome is therefore twofold: establish what happened in the specific case and close the process gap that would allow a similar scheme to recur with different people.

Strong supply-chain fraud controls join prevention and investigation

Supplier due diligence, payment verification, segregation of duties, stock controls and audit trails reduce opportunity. When concerns still arise, rapid evidence preservation and an objective investigation give the business the best chance of understanding what happened and stopping further loss.

Suspect procurement, supplier or stock fraud?

We can help define the issue, preserve evidence and plan a proportionate factual investigation. Book a confidential consultation with Trojan Investigations.

Sources and References

  • Cabinet Office / GOV.UK — Procurement Act 2023 guidance: Exclusions, updated 17 August 2026.
  • Competition and Markets Authority / GOV.UK — Exclusion and debarment on competition grounds, published 26 February 2025.
  • Home Office / GOV.UK — Economic Crime and Corporate Transparency Act 2023: guidance on the offence of failure to prevent fraud.
  • HMRC / GOV.UK — Advice on applying supply chain due-diligence principles: check, act and review.
  • Fraud Act 2006.
  • Bribery Act 2010.
  • UK GDPR and Data Protection Act 2018.
  • Information Commissioner's Office — Personal data breach guidance.

Frequently Asked Questions About Supply Chain Fraud Investigations

Practical answers about procurement fraud, supplier collusion, fake invoices, payment diversion, counterfeit goods, due diligence, evidence preservation, surveillance, public procurement and reporting suspected fraud.


It is dishonest activity affecting sourcing, procurement, transport, warehousing, invoicing, payment or contract delivery. It can involve suppliers, employees, intermediaries or external criminals.

A ghost supplier is an entity used to generate payments without providing genuine goods or services. It may be completely fictitious or a real company controlled by someone connected to the fraud.

Look for patterns such as repeated awards to one supplier, weak competition, unusual emergency purchasing, price anomalies, connected people and approvals that bypass normal controls. Evidence must then be verified.

Purchase orders, contracts, tender files, supplier onboarding records, invoices, payment-change requests, email records, audit logs, CCTV, stock records and delivery documentation are common priorities.

Employers may have lawful access to some business communications, but monitoring and review must have a proper purpose and comply with data-protection and employment obligations. Scope should be defined carefully.

Yes where there is a defined lawful purpose, such as observing public meetings or suspected unauthorised movement of goods. It should be targeted and proportionate.

No. Its exclusions regime is for covered public procurement. Private businesses can adopt similar risk-based due-diligence principles without being directly subject to those public-procurement rules.

It occurs when criminals pretend to be a genuine supplier, often to change payment details or redirect money. Independent verification through a known contact route is a key defence.

Use an independently known telephone number or other trusted channel and verify the change with an authorised contact. Do not rely on contact details contained only in the change request.

Yes. Preserve the goods, packaging, serial or batch identifiers, contracts, invoices and provenance records. Technical authentication may require the manufacturer, rights holder or an expert.

It is a corporate offence introduced by the Economic Crime and Corporate Transparency Act 2023 for qualifying large organisations. It came into effect on 1 September 2025 and is linked to reasonable fraud-prevention procedures.

Not necessarily. Premature confrontation can cause evidence to disappear or accounts to be coordinated. Consider containment, preservation, HR and legal advice before deciding how and when to interview.

Serious or ongoing criminal fraud, theft, bribery, threats or organised activity may require police involvement. A private investigation does not replace police powers.

Potentially. A factual, properly sourced report can support legal decision-making, but admissibility and litigation strategy should be determined with the client’s solicitor.

Combine supplier due diligence, segregation of duties, independent payment verification, controlled access, audit trails, stock controls, staff reporting routes and periodic review of higher-risk suppliers.



Five-Star Rated Private Investigator

With a wealth of five-star reviews, Trojan Investigations is a highly rated, professional, and trustworthy private investigation service expertly led by Anthony Butlin, whose 25 years of covert policing experience ensures every case is handled with precision, discretion, and unparalleled expertise.