The company’s internal report may be the starting point for police attention, but the criminal case still requires independent proof. The defense must understand the internal investigation closely enough to identify what is original evidence, what is interpretation and what may have been omitted from the company’s narrative.
A Wenzhou manufacturer conducts an internal anti-fraud investigation and accuses a procurement employee of taking kickbacks and helping suppliers inflate prices. The company collected work emails, access logs and interview notes before reporting the matter to police. The employee says the internal investigation was one-sided. The Criminal Law and Criminal Procedure Law provide the substantive and procedural framework, with electronic-data rules and the 2026 confession-and-punishment guidance relevant where the facts require them.[1][2][3][4]
Internal-investigation material needs provenance. Counsel should identify who collected the data, how interviews were recorded and whether the original source records have been preserved. The defense gains credibility by explaining what the document proves, what it does not prove and whether another record changes the inference about knowledge, authority or benefit. [2][3] The defense should work backward from the company’s internal report to the original email, ERP record, interview recording, bank transfer or supplier document supporting each conclusion. [2][3]
The specific problem
The Legal Rule
In Wenzhou, treat defending an employee accused of corporate fraud as a question of internal investigations, digital evidence and personal criminal responsibility. Naming the city does not replace the papers, approvals or forum that actually control the outcome.
The Business Impact
In Wenzhou, confirm the documents, authority and local filings for this defending an employee accused of corporate fraud matter before you pay, transfer or sue. The city name is not a substitute for the file.
Internal-investigation material should be treated as evidence with a provenance
Internal policy breaches and criminal offenses use different standards; the report may establish a compliance failure without proving the charged offense. The internal report should be treated as a map to source evidence, not as proof by itself. Every material conclusion should be linked to the original email, access log, payment, interview recording or procurement record on which it rests. This is especially important when the company selected only part of a message thread or summarized an employee interview. The criminal case should allow the underlying material to be checked independently under the applicable evidence rules.
Applied to internal-investigation material should be treated as evidence with a provenance, where the company used outside investigators or forensic vendors, defense counsel should identify their instructions, scope and source data. A vendor report may contain useful technical analysis, but assumptions about account ownership or employee responsibility should be tested against the underlying logs and corporate access model.
Procurement authority needs a decision map
Procurement authority should be broken into recommendation, price approval, contracting, receipt and payment. Those functions are often distributed among several employees. [1][2] Procurement responsibility should be divided among recommendation, price approval, contracting, receipt and payment rather than assigned to the employee with the most visible role. [1][2] Internal policy breaches and criminal offenses use different standards; the report may establish a compliance failure without proving the charged offense.
Procurement authority should be decomposed. The employee who recommends a supplier may not control final price, contract signature, receipt certification or payment. If two managers also approve the transaction, their role and information should be examined. A hidden benefit can remain important, but the prosecution still needs to show how the defendant’s authority and conduct produced the alleged company loss or satisfied the charged offense. Procurement authority should be broken into recommendation, price approval, contracting, receipt and payment. Those functions are often distributed among several employees. The defense should then state which source record confirms or contradicts that proposition and how resolution of the point changes the prosecution theory or sentencing analysis.
A related payment is not automatically a kickback
Related-party transactions need commercial substance. The defense should examine contracts, services, pricing, repayment and personal benefit before accepting either a legitimate-business or diversion narrative. [1][4] A supplier payment should be traced against any claimed loan, service or personal relationship before the company’s kickback label is adopted. [1][4] Market-price analysis should use comparable specifications and timing, while digital evidence should preserve complete threads and metadata rather than selected excerpts.
Internal policy language should not be imported into criminal law without analysis. A conflict-of-interest breach, poor procurement process or undisclosed relationship may justify discipline while still falling short of the criminal charge. Conversely, serious policy violations can be evidence of concealment or knowledge. Defense counsel should identify the actual conduct first and then test it against the statutory offense rather than arguing from the company’s label. Related-party transactions need commercial substance. The defense should examine contracts, services, pricing, repayment and personal benefit before accepting either a legitimate-business or diversion narrative. The defense should then state which source record confirms or contradicts that proposition and how resolution of the point changes the prosecution theory or sentencing analysis.
Digital evidence can reveal both conduct and investigative bias
[2][3] The defense should work backward from the company’s internal report to the original email, ERP record, interview recording, bank transfer or supplier document supporting each conclusion. [2][3] Market-price analysis should use comparable specifications and timing, while digital evidence should preserve complete threads and metadata rather than selected excerpts. The internal report should be treated as a map to source evidence, not as proof by itself. Every material conclusion should be linked to the original email, access log, payment, interview recording or procurement record on which it rests. This is especially important when the company selected only part of a message thread or summarized an employee interview. The criminal case should allow the underlying material to be checked independently under the applicable evidence rules.
The defense should connect the disputed fact to a statutory element or procedural consequence and test the prosecution inference against contemporaneous source records. The defense should then state which source record confirms or contradicts that proposition and how resolution of the point changes the prosecution theory or sentencing analysis.
Applied to digital evidence can reveal both conduct and investigative bias, if a supplier relationship pre-dated the employee’s role, that history can be relevant to both pricing and alleged personal influence. Conversely, a supplier introduced by the employee shortly before unusual payments began may require closer examination. The chronology should connect relationship, procurement decision and benefit rather than treating them as separate suspicious facts.
Price inflation needs a commercial baseline
Price comparison requires genuinely comparable specifications, timing and service conditions. An expensive purchase can reflect misconduct, but it can also reflect different quality, urgency or terms. Statements, payment data, internal approvals and electronic logs are strongest when they corroborate one another rather than when one item is asked to carry the entire theory. [1][2] Procurement responsibility should be divided among recommendation, price approval, contracting, receipt and payment rather than assigned to the employee with the most visible role. [1][2] The defense should acknowledge genuine control failures but insist that personal benefit, knowledge and authority be proved from source evidence.
Procurement authority should be decomposed. The employee who recommends a supplier may not control final price, contract signature, receipt certification or payment. If two managers also approve the transaction, their role and information should be examined. A hidden benefit can remain important, but the prosecution still needs to show how the defendant’s authority and conduct produced the alleged company loss or satisfied the charged offense.
Applied to price inflation needs a commercial baseline, where the company used outside investigators or forensic vendors, defense counsel should identify their instructions, scope and source data. A vendor report may contain useful technical analysis, but assumptions about account ownership or employee responsibility should be tested against the underlying logs and corporate access model.
Corporate interviews and police evidence require separate provenance
Corporate interview notes are summaries generated in an employment context. They should be compared with recordings, original notes and later formal statements before being treated as definitive admissions. Evidence collected by a company and evidence collected under criminal procedure are not interchangeable. The defense should track how internal material was transferred into the formal case. Statements, payment data, internal approvals and electronic logs are strongest when they corroborate one another rather than when one item is asked to carry the entire theory.
A supplier payment should be traced against any claimed loan, service or personal relationship before the company’s kickback label is adopted. [1][2] The defense should acknowledge genuine control failures but insist that personal benefit, knowledge and authority be proved from source evidence. Internal policy language should not be imported into criminal law without analysis. A conflict-of-interest breach, poor procurement process or undisclosed relationship may justify discipline while still falling short of the criminal charge. Conversely, serious policy violations can be evidence of concealment or knowledge. Defense counsel should identify the actual conduct first and then test it against the statutory offense rather than arguing from the company’s label.
Other employees’ roles can affect personal responsibility
Transfers through a personal account should be separated by purpose and duration. Pass-through payments, expense advances and personal use can have very different legal significance. [1][2] The defense should work backward from the company’s internal report to the original email, ERP record, interview recording, bank transfer or supplier document supporting each conclusion. [1][2]
Internal policy breaches and criminal offenses use different standards; the report may establish a compliance failure without proving the charged offense. The internal report should be treated as a map to source evidence, not as proof by itself. Every material conclusion should be linked to the original email, access log, payment, interview recording or procurement record on which it rests. This is especially important when the company selected only part of a message thread or summarized an employee interview. The criminal case should allow the underlying material to be checked independently under the applicable evidence rules. In employee criminal defense after an internal anti-fraud investigation, counsel should preserve the adverse fact as part of the chronology and explain why it does or does not alter the prosecution theory, rather than omitting it from a later submission.
Transfers through a personal account should be separated by purpose and duration. Pass-through payments, expense advances and personal use can have very different legal significance. The defense should then state which source record confirms or contradicts that proposition and how resolution of the point changes the prosecution theory or sentencing analysis.
Restitution and disciplinary action have different legal functions
Procurement responsibility should be divided among recommendation, price approval, contracting, receipt and payment rather than assigned to the employee with the most visible role. [1][2] Internal policy breaches and criminal offenses use different standards; the report may establish a compliance failure without proving the charged offense. Procurement authority should be decomposed. The employee who recommends a supplier may not control final price, contract signature, receipt certification or payment. If two managers also approve the transaction, their role and information should be examined. A hidden benefit can remain important, but the prosecution still needs to show how the defendant’s authority and conduct produced the alleged company loss or satisfied the charged offense.
Restitution should be reconciled against a defensible transaction schedule. Payment can reduce harm and support mitigation, but it should not silently concede a disputed criminal amount or mental state. The defense should then state which source record confirms or contradicts that proposition and how resolution of the point changes the prosecution theory or sentencing analysis.
Applied to restitution and disciplinary action have different legal functions, if a supplier relationship pre-dated the employee’s role, that history can be relevant to both pricing and alleged personal influence. Conversely, a supplier introduced by the employee shortly before unusual payments began may require closer examination. The chronology should connect relationship, procurement decision and benefit rather than treating them as separate suspicious facts.
A defense can acknowledge compliance failures without conceding the offense
Internal compliance records can cut both ways. Written advice, training and escalation may support a good-faith explanation, while ignored warnings or fabricated records can strengthen an inference of knowledge. Statements, payment data, internal approvals and electronic logs are strongest when they corroborate one another rather than when one item is asked to carry the entire theory. A supplier payment should be traced against any claimed loan, service or personal relationship before the company’s kickback label is adopted. [1][2]
Market-price analysis should use comparable specifications and timing, while digital evidence should preserve complete threads and metadata rather than selected excerpts. Internal policy language should not be imported into criminal law without analysis. A conflict-of-interest breach, poor procurement process or undisclosed relationship may justify discipline while still falling short of the criminal charge. Conversely, serious policy violations can be evidence of concealment or knowledge. Defense counsel should identify the actual conduct first and then test it against the statutory offense rather than arguing from the company’s label.
Applied to a defense can acknowledge compliance failures without conceding the offense, where the company used outside investigators or forensic vendors, defense counsel should identify their instructions, scope and source data. A vendor report may contain useful technical analysis, but assumptions about account ownership or employee responsibility should be tested against the underlying logs and corporate access model.
An internal investigation report is not the underlying evidence
A company’s anti-fraud report can organize facts, but it is a secondary document created for a corporate purpose. Defense counsel should identify the source material behind each conclusion: original email, bank transaction, ERP record, interview recording or supplier document. The electronic-data rules become relevant when those digital materials enter the criminal case because authenticity, collection and completeness need to be assessed under the criminal-evidence framework.[2][3] This distinction also helps identify investigative selection. If the report quotes five messages from a thread of hundreds, the full conversation may alter context. If an interview note summarizes an employee’s words, the original recording or contemporaneous notes may reveal nuance. The defense should not assume that the internal investigation was improper, but it should insist that criminal conclusions rest on verifiable source evidence rather than the company’s characterization alone. [2][3]
The defense should work backward from the company’s internal report to the original email, ERP record, interview recording, bank transfer or supplier document supporting each conclusion. [2][3] Market-price analysis should use comparable specifications and timing, while digital evidence should preserve complete threads and metadata rather than selected excerpts. The internal report should be treated as a map to source evidence, not as proof by itself. Every material conclusion should be linked to the original email, access log, payment, interview recording or procurement record on which it rests. This is especially important when the company selected only part of a message thread or summarized an employee interview. The criminal case should allow the underlying material to be checked independently under the applicable evidence rules.
Fraud allegations require a precise representation and mental-state analysis
Where the company describes the employee’s conduct as “fraud,” counsel should identify the statutory offense actually alleged and the false representation or deceptive act said to satisfy it. The Supreme People’s Court and Supreme People’s Procuratorate’s fraud interpretation provides offense-specific guidance on fraud cases, but the factual theory still depends on what the employee represented, knew and obtained.[4] In a procurement case, inflated pricing and secret supplier payments may support a different criminal theory from classic external fraud, so terminology matters. The defense should not allow an internal compliance label to substitute for the prosecution’s legal characterization. It should map benefit, authority, supplier relationship and company loss and then test those facts against the actual charge. This helps separate poor controls, conflicts of interest and disciplinary breaches from the conduct required for criminal conviction. [1][4]
Procurement responsibility should be divided among recommendation, price approval, contracting, receipt and payment rather than assigned to the employee with the most visible role. [1][4] The defense should acknowledge genuine control failures but insist that personal benefit, knowledge and authority be proved from source evidence. Procurement authority should be decomposed. The employee who recommends a supplier may not control final price, contract signature, receipt certification or payment. If two managers also approve the transaction, their role and information should be examined. A hidden benefit can remain important, but the prosecution still needs to show how the defendant’s authority and conduct produced the alleged company loss or satisfied the charged offense.
Internal investigators should distinguish policy breaches from criminal propositions
Corporate investigations often begin under employment or compliance policies that use standards different from criminal law. An employee may violate a conflict-of-interest policy by failing to disclose a relationship with a supplier even if the evidence does not establish the elements of the criminal offense later alleged. The internal report should therefore be read with attention to what standard it applied. For defense counsel, this distinction can be critical. Evidence that proves a disciplinary breach may still be relevant, but it should not be described as if the company has already established criminal guilt. The prosecution must prove the statutory offense under criminal procedure. Conversely, the defense should not dismiss a serious policy breach merely because the company used non-criminal terminology. The correct approach is to identify the underlying conduct and test it independently against the charge. [2][3]
A supplier payment should be traced against any claimed loan, service or personal relationship before the company’s kickback label is adopted. [2][3] The defense should acknowledge genuine control failures but insist that personal benefit, knowledge and authority be proved from source evidence. Internal policy language should not be imported into criminal law without analysis. A conflict-of-interest breach, poor procurement process or undisclosed relationship may justify discipline while still falling short of the criminal charge. Conversely, serious policy violations can be evidence of concealment or knowledge. Defense counsel should identify the actual conduct first and then test it against the statutory offense rather than arguing from the company’s label.
Case study: applying the framework
Assume the employee recommended a supplier owned by a former classmate and received RMB 300,000 from that person over two years. The employee says RMB 200,000 was repayment of a private loan. The company’s procurement system shows that two managers had to approve final prices, but internal investigators interviewed only one of them before reporting the case. The defense would compare the company’s internal report with the underlying source evidence before accepting any conclusion. The RMB 300,000 payment would be split into the claimed loan repayment and the remaining amount, with bank history and communications used to test each explanation.[1][2][3] Procurement authority would be mapped across the employee and approving managers, while market evidence would test the alleged price inflation. If interview notes differ from recordings or raw messages, the defense can challenge the particular conclusion without claiming the entire internal investigation is invalid.
If the original interview recording shows that the employee qualified an answer later summarized as an admission, that difference should be presented precisely. The defense should not claim the entire corporate investigation is unreliable when a narrower source-record discrepancy is enough to challenge the relevant conclusion. The defense should also preserve the original internal-investigation data set so expert or court review can test whether the company’s report omitted communications or approvals that materially change the employee’s role. Any expert review should work from the preserved source records rather than the company’s narrative summary, especially where system access or transaction timing remains contested.
Conclusion
An internal anti-fraud investigation can explain why a company reported an employee, but the report is not the criminal case itself. The prosecution must rely on source evidence, and the defense should work backward from corporate conclusions to original emails, access logs, payments and interview records.[2][3] In procurement cases, that source-level review is particularly important because authority and benefit may be distributed across several people. A policy breach can be serious without proving the criminal offense, while a hidden supplier payment can become highly significant when linked to pricing and approval conduct. The defense is strongest when it acknowledges genuine compliance failures but insists on separate proof of the statutory elements and the individual employee’s culpability.
Legal and regulatory sources
[1] Criminal Law of the People’s Republic of China — [official source](https://gongbao.court.gov.cn/Details/96fea4e0b9e00def2295a1e598666f.html) [2] Criminal Procedure Law of the People’s Republic of China — [official source](https://www.npc.gov.cn/c2/c12435/201905/t20190521_276591.html) [3] SPC/SPP/MPS Provisions on Electronic Data in Criminal Cases — [official source](https://www.court.gov.cn/fabu/xiangqing/26431.html) [4] SPC/SPP Interpretation on Criminal Cases of Fraud — [official source](https://www.court.gov.cn/zixun/xiangqing/32891.html)
General legal information only; not legal advice for a specific matter.
Discussion
Share experience or questions about this topic. This is a public discussion — not legal advice. Do not post confidential case details.
Have a question after reading? Leave it here, or Ask a Lawyer for a free initial intake.
Comments are moderated. China Legal Portal is a directory and information resource; no attorney–client relationship is formed by posting here.