An offence committed at company premises or through company systems does not automatically make every director or employee liable. Liability depends on the applicable law, conduct, authority, knowledge, intent and evidence.
Four positions to examine
The direct actor
Who executed the transfer, created the record or made the representation? A user account must be linked to the actual person and conduct.
Assisting persons
Did anyone agree, facilitate, conceal or knowingly support the act? Proximity in the organisation is not enough by itself.
Directors and authorised officers
The file must distinguish decision-making, delegation, supervision and actual contribution. A management title is relevant, but it does not replace proof of the acts or statutory duties in issue.
The legal person
Entity liability and available sanctions depend on the specific statute. The assessment should examine whether the conduct was connected with the entity's interest, organs, policies or systems.
Evidence beyond the organisation chart
Review signature matrices, system access, correspondence, money flows, temporary delegations and control overrides. The internal investigation should answer who did what, under which authority and for whose benefit.
Board and management decisions
- Contain the immediate risk to funds and Personal Data.
- Ensure independence and manage conflicts of interest.
- Decide the timing of reporting and cooperation.
- Preserve the company's private-right claim.
- Remediate control failures without prejudging individuals.
For urgent discovery, start with the first 24 hours protocol. For criminal characterisation, see Employee Fraud Against the Company.