Alleged bookkeeping offences: what to do in the first ten days comes down to three moves, done in this order: preserve every record exactly as it stands, get a precise written account of what is alleged and who raised it, and take advice before anyone in the company answers a single question informally. Anything destroyed, tidied up or explained away in this window becomes evidence against whoever did it, not just against the company.
Who this concerns
This situation reaches four groups almost every time. The board member who receives a notification from the auditor that a matter has been reported under the auditor's duty to flag suspected crime. The finance director or CFO who is told that Ekobrottsmyndigheten, the Swedish Economic Crime Authority, has opened a preliminary investigation into the company's bookkeeping. The accounting staff member who is asked to "just explain" an entry to an investigator over the phone. And the director of a subsidiary who learns, often second-hand, that a parent company abroad has been asked the same questions in parallel.
None of these positions is the same as being formally suspected of a crime, and confusing them is the first mistake most people make. A notification is not a charge. A request for documents is not an accusation. But the ten days after any of these four triggers determine, more than anything that happens later, whether the eventual position is defensible.
What the law says
Under Swedish law as it currently stands, an accounting offence, bokföringsbrott, does not require an intention to defraud anyone. It attaches to the state of the books themselves: records that were not kept when required, records that were kept in a way that is materially misleading, or a failure to preserve records in a condition that allows the company's development, financial result and position to be assessed within the correct time. That last point is the one that trips up commercial clients: the offence can exist even where no money went missing and no third party lost a krona. Bad bookkeeping is, on its own, capable of being the offence.
Liability is personal. It attaches to whoever, within the company, was actually responsible for the state of the accounts at the relevant time, which in practice means the person who signed off on the accounting function, not necessarily the person whose name is on the annual report. Board members who delegated the accounting function without checking how it was being run are not automatically protected by the delegation. Where records are missing, incomplete, or were destroyed after a problem became apparent, the question shifts from "was there an offence" to "who is responsible for the state we're now in," which is a considerably harder question to answer well once the first ten days have already been spent doing the wrong things.
How it works in practice
Day one: stop, do not explain
The single most damaging action in the first ten days is an informal explanation offered to make the problem go away. A finance manager who tells an investigator "that entry is fine, I can explain it" without having reviewed the underlying documents first has created a statement that cannot be unsaid. Nothing should be explained to anyone outside the company, and very little inside it, until the underlying records have been pulled and reviewed by someone who was not responsible for creating them.
Preserve records exactly as they stand
This means a litigation hold in substance, whether or not that phrase is used internally: no deletion of emails, no "cleaning up" of the accounting system, no retroactive corrections to entries that look wrong, and no destruction of drafts, working papers or correspondence connected to the accounts in question. A correction made after the fact, even one that is technically accurate, looks like tampering and will be treated as such. If a genuine correction is needed, it is made openly, dated, and documented as a correction, never quietly folded into the original entry.
Get the allegation in writing
Whoever raised the concern, whether an auditor, an authority, or an internal whistleblower, should be asked, in writing, exactly what is being alleged: which entries, which period, which entity. Companies routinely spend the first ten days responding to a version of the allegation they assumed rather than one that was actually made. That assumption is expensive to correct later.
Map who had control of the books
Before any external response is drafted, establish internally who actually controlled the accounting function during the relevant period: who entered data, who reviewed it, who signed off, and who had authority to override entries. This map is not for anyone outside the company yet. It exists so that advice can be accurate about where personal exposure actually sits, rather than defaulting to whoever happens to be most senior.
Separate the company's position from any individual's position
A company and the individual who ran its books do not necessarily have the same interests once an investigation starts. Legal advice given to "the company" without addressing this early can leave an individual director or accountant relying on advice that was never actually given with their personal exposure in mind. This needs to be resolved explicitly, not left ambiguous by default.
Notify insurers and check disclosure duties
Directors' and officers' cover and any relevant crime cover typically carry strict notification windows, often shorter than ten days from the point the company became aware of the matter. Missing that window can void cover regardless of the merits of the underlying allegation. Listed and larger private companies also need to check, separately, whether the matter triggers a disclosure obligation of its own; that question is distinct from the criminal exposure and is dealt with in more depth in the material on disclosure risk for listed companies.
Control internal communication
An internal email asking staff to "please be careful with the accounts going forward" is routinely produced later as evidence that the problem was known internally before it was reported. Any internal communication about the matter should go through whoever is coordinating the response, not through the ordinary management chain.
What to check in the first ten days
- Which specific entries, periods and legal entities the allegation actually covers, in writing.
- Who had operational and sign-off control of the accounts during the period in question.
- Whether any correction, deletion or system change has already happened since the concern arose.
- The notification deadlines under D&O and crime insurance policies, and whether they have already started running.
- Whether the same accounting function serves other group entities, particularly any outside Sweden.
- Whether a parallel civil claim, tax audit or contract dispute touches the same records.
- Whether any employee involved has already spoken informally to an investigator or auditor without a record of what was said.
Frequently asked
Does an internal investigation before any report to Ekobrottsmyndigheten protect the company?
It can help establish that the company acted responsibly once it became aware of a problem, but it does not prevent an offence from having occurred and it does not substitute for legal advice on whether and how to report. An internal review run without proper scoping can also contaminate evidence or create new statements that make the position harder to defend, so its terms of reference matter as much as the decision to run it at all.
Can a director be held personally liable for a bookkeeping offence committed by accounting staff?
Personal liability follows actual responsibility for the state of the accounts, not job title. A director who delegated the accounting function but never checked how it was run, or who continued to sign off on accounts after being told something was wrong, can be exposed even without having entered a single transaction personally.
What happens if records needed to answer the allegation are held by a foreign parent company?
The Swedish entity remains responsible for producing what Swedish law requires it to be able to produce, regardless of where the underlying data physically sits. A parent company's reluctance or delay in releasing records does not extend the Swedish entity's own deadlines, and this gap is one of the most common reasons the first ten days are lost without any real progress being made.
The numbers
There is no fixed price for defending an alleged bookkeeping offence, and any figure quoted before the scope of the allegation is known should be treated with suspicion. What actually drives cost is, first, the volume and condition of the underlying records: a company with clean, complete accounting data spends far less than one where records have to be reconstructed from bank statements and supplier correspondence. Second, the number of individuals whose positions need to be assessed separately, since each person whose personal exposure differs from the company's position typically needs advice addressed to them specifically. Third, whether the matter is confined to Sweden or touches a parent, subsidiary or contract counterparty abroad, which adds a layer of coordination that a purely domestic matter does not have. Fourth, how much of the first ten days was spent well: a company that preserved records, wrote down the allegation precisely and mapped responsibility early generally spends less overall than one that has to unwind informal explanations already given.
Where it usually goes wrong
The most common failure is treating the first ten days as a waiting period rather than a working period. Nothing formal may have happened yet, no charge, no summons, but the position that will eventually be defended or not defended is being built during exactly this window, largely by what is or is not preserved and what is or is not said informally.
The second failure is assuming that because the company reported the matter itself, or cooperated fully, individual directors are automatically covered by that cooperation. They are not. A company's decision to cooperate is a company decision; it does not resolve whether a specific individual had personal control over the accounts, and it can, in some configurations, work against that individual if the company's account of events shifts responsibility onto them specifically.
The third failure appears where the group has a foreign element: a parent company outside Sweden, accounting functions shared across entities, or contracts where a counterparty abroad holds records relevant to the Swedish entity's accounts. In that configuration, requests for documents that would be routine domestically become slow, contested, or subject to a different legal regime for data access. A Swedish company cannot rely on a foreign parent's own timetable to meet its own obligations, and assuming otherwise is one of the more expensive mistakes made in this period. Where a parent company is itself listed, or where the group's disclosure obligations are triggered on a consolidated basis, the position becomes genuinely two-track: a Swedish criminal exposure running alongside a separate disclosure question that follows its own rules and its own clock.
The fourth failure is treating this as purely defensive. Where the underlying facts show the company itself was the victim of a director or employee's conduct, for example where accounts were falsified to conceal a separate misappropriation, the company may have its own claim against that individual. That question sits alongside, not instead of, the criminal exposure, and pursuing it, including enforcement against a director personally where assets have been moved, is a separate track that needs its own early assessment rather than being left until the criminal matter concludes.
What to do next
Self-directed work in the first ten days covers preservation, getting the allegation in writing, and mapping who controlled the accounts. It does not cover deciding whether the company should make its own report, how to respond to a formal request for documents, or how to separate the company's position from an individual director's position once those interests start to diverge. That is where an assessment of the actual exposure, based on the specific entries and period in question, needs to start.
Lodline's economic crime defence practice works from exactly this point: reviewing what has already happened in the first days, establishing where personal and company exposure actually sit, and setting out what the realistic range of outcomes looks like before any further step is taken. Start with an assessment of the specific allegation rather than a general conversation about bookkeeping offences.