Post Office Limited - Horizon
When system-generated shortfalls were treated as evidence, who tested the system?
The Court of Appeal found a material risk that apparent branch shortfalls were caused by Horizon bugs, errors or defects and quashed 39 appellants' convictions in 2021; legislation in 2024 then quashed qualifying convictions more broadly.
Documented impact
Authoritative findings
The documented event
On 23 April 2021, the Court of Appeal considered 42 cases referred by the Criminal Cases Review Commission. It accepted that, throughout the relevant period, significant problems with Horizon created a material risk that an apparent branch shortfall did not represent missing cash or stock but was caused by bugs, errors or defects. The court found that Post Office Limited knew there were serious reliability issues, yet did not adequately investigate reported problems or make relevant disclosure in the cases. The court allowed 39 appeals and quashed the appellants' convictions; three appeals were dismissed because Horizon reliability was not essential to those prosecution cases. The Post Office (Horizon System) Offences Act 2024 subsequently quashed qualifying convictions in England, Wales and Northern Ireland. Separate Scottish legislation received Royal Assent on 13 June 2024. The Horizon Convictions Redress Scheme offers eligible applicants a £600,000 optional fixed settlement or a detailed assessment.
Hypothetical institutional scenario
How might the same control pattern appear?
A system reports a shortfall against a local operator. The organisation treats the system output as the starting truth and asks the operator to explain the difference. Similar challenges have been raised elsewhere, but complaints are handled individually and do not trigger independent technical review. Disciplinary or legal action proceeds without corroborating evidence of an actual loss.
Stress-test questions
Questions for challenge and assurance
-
Operations
When a system flags a discrepancy, what evidence tests the integrity of the system output before the organisation investigates the individual?
-
Operations
Can an affected user trigger an independent technical review, and are similar challenges aggregated to identify a recurring defect?
-
Audit
What corroboration is required before disciplinary, financial or legal action can rely on system-generated data?
-
Board
If a material defect were discovered, could the organisation identify every consequential decision that relied on the affected system output?
NFRisk practitioner interpretation
Control implication
Where system output can trigger financial, disciplinary or legal consequences for a person, reliability must be tested before action is taken. Required evidence includes the relevant error paths, audit trail, independent corroboration, disclosure of known defects and a route for affected users to trigger technical review. Repeated challenges to system output are potential control signals, not merely complaints to be closed.
Framework relevance
Explicitly labelled analytical mappings
COSO ERM lens: Review & Revision
NFRisk maps the Court of Appeal's findings that reported system problems were not adequately investigated or disclosed to COSO's Review & Revision component. This is a retrospective analytical mapping, not a finding made by the court or COSO.
Enterprise Risk Management - Integrating with Strategy and Performance · Committee of Sponsoring Organizations of the Treadway Commission (COSO)Evidence register
Primary and supporting sources
-
Court of Appeal (Criminal Division), Judiciary of England and Wales
Hamilton and Others v Post Office Limited [2021] EWCA Crim 577 (opens in a new tab) 23 April 2021 · Authoritative primary source -
UK Parliament / legislation.gov.uk
Post Office (Horizon System) Offences Act 2024 and Explanatory Notes (opens in a new tab) 24 May 2024 · Authoritative primary source -
Scottish Parliament / legislation.gov.uk
Post Office (Horizon System) Offences (Scotland) Act 2024 (opens in a new tab) 13 June 2024 · Authoritative primary source -
UK Department for Business and Trade
Horizon Convictions Redress Scheme: applying for financial redress (opens in a new tab) 30 July 2024 · Authoritative primary source -
COSO
Enterprise Risk Management - Integrating with Strategy and Performance (opens in a new tab) 1 June 2017 · Authoritative primary source
Publication note
A documented external event—not an NFRisk client engagement.
The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.
Return to the Risk Scenario LibraryFrom scenario to mandate
Test the equivalent control assumption in your environment.
NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.