Supply-chain fraud is rarely one single offence or one single weak control. It can involve dishonest suppliers, employees, intermediaries, subcontractors or criminals impersonating genuine businesses. The investigation therefore has to reconstruct the commercial process: who approved the supplier, who changed the bank details, who received the goods, what was invoiced, what was paid and what evidence exists at each stage.
At Trojan Investigations, we support organisations through business investigations involving suspected procurement fraud, stock theft, supplier deception, employee collusion and related misconduct. Our role is to establish facts, preserve evidence and help the client decide what should happen next.
Originally published: 14th July 2026 | Updated: 7th September 2026
How should a business investigate suspected supply-chain fraud?
Preserve the records first, control further loss without alerting suspects unnecessarily, build a chronology of procurement and payment decisions, compare invoices to contracts and delivery evidence, identify who had authority at each stage, verify suppliers independently and escalate to legal, regulatory or police channels where the evidence requires it.
Supply-Chain Fraud Is Broader Than Fake Invoices
A supply chain may be attacked at tendering, onboarding, ordering, transport, warehousing, invoicing, payment or contract management. Fraud can be external — for example a fake supplier payment request — or internal, such as an employee creating a connected company and steering orders towards it.
| Fraud pattern | Typical mechanism | Evidence to preserve |
|---|---|---|
| Supplier impersonation | Criminal changes bank details or impersonates an existing supplier | Original emails, headers, payment-change requests, call logs and bank records |
| Procurement collusion | Employee and supplier manipulate quotations, orders or pricing | Tender files, approvals, messaging, pricing history and relationship links |
| Ghost supplier | Payments made to an entity that does not provide genuine goods or services | Onboarding documents, bank details, invoices, delivery evidence and ownership information |
| Invoice inflation or duplication | Charges exceed contract terms or the same item is paid more than once | Contracts, purchase orders, invoice register and payment ledger |
| Stock diversion | Goods are removed, substituted or diverted before reaching the intended destination | Warehouse records, CCTV, manifests, vehicle logs and stock counts |
| Counterfeit or substituted goods | Lower-grade or fake products are supplied as genuine | Batch numbers, specification records, samples, inspection results and supplier chain |
Start by Containing Loss Without Destroying Evidence
Once fraud is suspected, there is often pressure to suspend staff, contact suppliers or change systems immediately. Some controls may be necessary to prevent further loss, but poorly planned action can delete logs, overwrite CCTV, trigger document destruction or alert people who are coordinating their accounts.
Immediate preservation priorities may include:
- Purchase orders, approvals, tender documents and supplier onboarding records.
- Invoice registers, payment instructions and bank-detail change requests.
- Email and collaboration-platform material retained through the organisation's lawful IT processes.
- Access logs, audit trails and user-account records.
- Warehouse, delivery, vehicle and stock-control records.
- CCTV footage before routine retention periods overwrite it.
- Contracts, specifications, quality reports and goods-received notes.
Supplier Verification Should Go Beyond a Name Match
A company can exist legally and still present fraud risk. Verification may include ownership and control, directors, trading history, address credibility, sanctions exposure, insolvency indicators, litigation or regulatory history where lawfully available, and whether the supplier appears capable of delivering the goods or services being purchased.
HMRC supply-chain guidance uses a useful “check, act and review” approach: test the credibility and legitimacy of suppliers and transactions, act on warning signs, then keep the risk under review rather than treating onboarding as a one-off exercise.
Procurement Collusion Often Hides in the Approval Process
Employee collusion can involve kickbacks, tailored tender specifications, fake competition, confidential bid information, unexplained single-source awards, repeated emergency purchasing or approval splitting designed to stay below financial limits.
The investigation should map who initiated, approved and benefited from each decision. Personal relationships are relevant only where they connect to a business decision; the goal is not to investigate employees' private lives generally.
Public Procurement Has a Specific 2025–2026 Legal Framework
For covered public procurement in England, Wales and Northern Ireland, the Procurement Act 2023 regime came into force on 24 February 2025. Current Cabinet Office guidance, updated in August 2026, requires authorities to consider mandatory and discretionary exclusion grounds and the risks presented by suppliers, connected persons and certain associated persons.
Public procurement rules are not the same as private-company purchasing rules
The Procurement Act exclusions regime is highly relevant to contracting authorities and suppliers competing for covered public contracts, but it should not be presented as a universal due-diligence rule for every private-sector purchase. Private businesses still benefit from the same risk questions — ownership, integrity, performance and conflicts — even where the Act itself does not apply.
Bid Rigging and Cartel Behaviour Need Specialist Escalation
Suspiciously coordinated bids, cover pricing, market sharing or suppliers taking turns to win work can indicate competition-law concerns. The Competition and Markets Authority has emphasised that the Procurement Act strengthened consequences for cartel activity in public procurement, including exclusion and potential debarment.
Where evidence points to anti-competitive behaviour rather than ordinary internal fraud, legal advice and appropriate reporting to the CMA may be required. A private investigation can help organise factual material, but it does not replace regulator powers.
Invoice Diversion Often Begins as Social Engineering
A supplier's email account may be compromised, or a criminal may use a lookalike domain and convincing signature block to request a bank-detail change. The safest control is independent verification using a known contact route, not replying to the message that requested the change.
When an incident has already happened, preserve the original message, headers, telephone numbers, bank details, payment authorisation history and the timeline of every internal decision. Contacting the bank quickly may also matter to any recovery attempt.
Stock, Cargo and Warehouse Fraud Need Physical Evidence
Inventory discrepancies can arise from genuine errors, poor systems or theft. Investigators compare stock records with goods-in/goods-out data, delivery documentation, access records, CCTV and vehicle movement. Patterns such as repeated shortages on one route or during one shift can narrow the enquiry without assuming guilt.
Where there is a defined activity to observe, lawful surveillance may help establish public movements, meetings or unauthorised removal of goods. It should be targeted and proportionate.
Counterfeit Goods Require Provenance, Not Just Suspicion
Suspected counterfeits should be preserved with packaging, batch identifiers, serial numbers, purchase records and a clear chain of custody. Technical comparison may require the manufacturer, rights holder or an appropriate expert.
A supplier's reluctance to provide provenance documents can be a warning sign, but the investigation should still distinguish poor administration from deliberate fraud.
Employee Data and Monitoring Must Be Handled Lawfully
Internal fraud investigations may involve staff emails, access logs, CCTV or other personal data. Employers remain responsible for data-protection compliance. Monitoring should have a defined purpose, lawful basis and proportionate scope, with access restricted to people who need the material for the investigation.
If a fraud incident also exposes personal data, the organisation may need to assess whether it is a reportable personal-data breach. That regulatory assessment should run in parallel with the fraud investigation rather than being overlooked because the main concern is financial loss.
Failure to Prevent Fraud May Matter to Larger Organisations
The Economic Crime and Corporate Transparency Act 2023 created a corporate offence of failure to prevent fraud for qualifying large organisations. The offence came into effect on 1 September 2025. Government guidance emphasises reasonable fraud-prevention procedures and a risk-based approach.
Not every supply-chain fraud triggers that offence, but the framework reinforces a broader governance point: organisations should understand how employees, agents and other associated persons could commit fraud for the organisation's benefit and design controls around those risks.
How We Structure a Supply-Chain Fraud Investigation
1. Define the suspected loss and period
We identify the transactions, products, suppliers or sites genuinely in question.
2. Preserve the original commercial records
Documents, logs, communications and CCTV are secured before routine deletion or informal editing changes the evidence.
3. Map people, approvals and money
We reconstruct who requested, approved, changed, delivered and received each relevant transaction.
4. Verify suppliers and relationships
Ownership, directorships, addresses and other public connections are checked where they are relevant to the suspected scheme.
5. Test alternative explanations
Control failures, error and poor administration are considered alongside deliberate fraud so the conclusion is evidence-led.
6. Report facts for the next decision
The final report separates verified findings from inference and identifies evidential gaps that may need legal, forensic or police powers.
Red Flags That Deserve Investigation
Red flags justify enquiry; they do not prove fraud. A well-run investigation should be capable of clearing innocent explanations as well as substantiating misconduct.
When to Involve Solicitors, Regulators or Police
If the suspected fraud is serious, ongoing, cross-border, connected to bribery or cartel conduct, or likely to result in litigation, early legal advice can protect privilege and shape evidence preservation. Criminal allegations may need to be reported to the police or the national fraud-reporting service, while competition concerns may fall within the CMA's remit.
Our legal and litigation support can be coordinated with the client's solicitors so the investigation produces material suitable for the decisions that follow.
Third-Party Access Can Be the Hidden Weak Point
Suppliers and contractors may have legitimate access to portals, stock systems, shared mailboxes, customer data or operational sites. Fraud risk increases when those permissions remain active after a contract changes, when subcontractors are not visible to the client or when several organisations share one generic account.
During an investigation, access rights should be mapped alongside financial approvals. Who could create or amend a supplier? Who could change bank details? Who could approve a goods-received note? Who could enter a warehouse or view delivery schedules? A fraud scheme often depends on combining two permissions that were never intended to sit together.
Conflicts of Interest Need Evidence, Not Assumptions
A personal connection between an employee and a supplier may be relevant, but it is not automatically fraudulent. The key question is whether the relationship affected a business decision or was concealed where disclosure was required.
Useful evidence can include company ownership, directorships, shared addresses, tender scoring, approval records, pricing history and communications that connect the relationship to the procurement decision. This is stronger than simply showing that two people know each other.
Interviews Should Follow the Documentary Evidence
Interviewing too early can allow suspects to tailor explanations around the questions being asked. Where possible, review the records first so the interviewer understands the chronology and can put specific discrepancies fairly to the person involved.
Witnesses should be asked open questions about the process they followed, what they knew at the time and which documents they relied on. The objective is to test the evidence, not to force a confession. HR and legal advisers should be involved where disciplinary rights or employment procedures are engaged.
Cross-Border Supply Chains Add Jurisdictional Limits
Overseas suppliers may involve different company registers, privacy laws, languages, banking systems and enforcement options. A UK investigator cannot assume that a method available domestically is lawful or effective abroad. Cross-border work should be planned around local legal advice and reliable in-country sources where necessary.
The same principle applies to recovery. Establishing that a payment or shipment went overseas does not by itself create a practical route to recover it. Early bank contact, insurer notification, legal advice and law-enforcement reporting may be more important than further private enquiry once the destination is known.
Contractual and Insurance Notifications Can Be Time-Critical
Fraud incidents may trigger contractual notice obligations, cyber or crime-insurance conditions, bank reporting requirements or duties to inform customers and regulators. Those deadlines can exist independently of the investigation. The organisation should therefore involve its legal, insurance, finance and data-protection contacts early rather than waiting for a final investigator's report.
The investigator's role is to preserve and organise the factual record so those advisers can make informed decisions. A clear chronology of discovery, containment, notifications and evidence handling can also help demonstrate that the business responded promptly.
Remediation Should Address the Route, Not Just the Individual
If the investigation substantiates fraud, removing one employee or supplier may not solve the control weakness that made the scheme possible. Review supplier onboarding, approval limits, conflicts declarations, payment-change verification, access rights, stock controls and audit logging.
The strongest outcome is therefore twofold: establish what happened in the specific case and close the process gap that would allow a similar scheme to recur with different people.
Strong supply-chain fraud controls join prevention and investigation
Supplier due diligence, payment verification, segregation of duties, stock controls and audit trails reduce opportunity. When concerns still arise, rapid evidence preservation and an objective investigation give the business the best chance of understanding what happened and stopping further loss.
Suspect procurement, supplier or stock fraud?
We can help define the issue, preserve evidence and plan a proportionate factual investigation. Book a confidential consultation with Trojan Investigations.
Sources and References
- Cabinet Office / GOV.UK — Procurement Act 2023 guidance: Exclusions, updated 17 August 2026.
- Competition and Markets Authority / GOV.UK — Exclusion and debarment on competition grounds, published 26 February 2025.
- Home Office / GOV.UK — Economic Crime and Corporate Transparency Act 2023: guidance on the offence of failure to prevent fraud.
- HMRC / GOV.UK — Advice on applying supply chain due-diligence principles: check, act and review.
- Fraud Act 2006.
- Bribery Act 2010.
- UK GDPR and Data Protection Act 2018.
- Information Commissioner's Office — Personal data breach guidance.