Skip to main content
NFRisk Non-Financial Risk advisory Start a Conversation
NFR-0044 Evidence-controlled risk scenario

Post Office Limited - Horizon

When system-generated shortfalls were treated as evidence, who tested the system?

The Court of Appeal found a material risk that apparent branch shortfalls were caused by Horizon bugs, errors or defects and quashed 39 appellants' convictions in 2021; legislation in 2024 then quashed qualifying convictions more broadly.

Data & Control Integrity Conduct & Governance Risk Data integrity Control assurance Governance & escalation System & back-out testing

Documented impact

42 cases Appeals considered by the Court of Appeal
39 appellants Convictions quashed by the Court of Appeal
£600,000 Optional fixed settlement under the redress scheme

Authoritative findings

The documented event

On 23 April 2021, the Court of Appeal considered 42 cases referred by the Criminal Cases Review Commission. It accepted that, throughout the relevant period, significant problems with Horizon created a material risk that an apparent branch shortfall did not represent missing cash or stock but was caused by bugs, errors or defects. The court found that Post Office Limited knew there were serious reliability issues, yet did not adequately investigate reported problems or make relevant disclosure in the cases. The court allowed 39 appeals and quashed the appellants' convictions; three appeals were dismissed because Horizon reliability was not essential to those prosecution cases. The Post Office (Horizon System) Offences Act 2024 subsequently quashed qualifying convictions in England, Wales and Northern Ireland. Separate Scottish legislation received Royal Assent on 13 June 2024. The Horizon Convictions Redress Scheme offers eligible applicants a £600,000 optional fixed settlement or a detailed assessment.

Hypothetical institutional scenario

How might the same control pattern appear?

A system reports a shortfall against a local operator. The organisation treats the system output as the starting truth and asks the operator to explain the difference. Similar challenges have been raised elsewhere, but complaints are handled individually and do not trigger independent technical review. Disciplinary or legal action proceeds without corroborating evidence of an actual loss.

Stress-test questions

Questions for challenge and assurance

  1. Operations

    When a system flags a discrepancy, what evidence tests the integrity of the system output before the organisation investigates the individual?

  2. Operations

    Can an affected user trigger an independent technical review, and are similar challenges aggregated to identify a recurring defect?

  3. Audit

    What corroboration is required before disciplinary, financial or legal action can rely on system-generated data?

  4. Board

    If a material defect were discovered, could the organisation identify every consequential decision that relied on the affected system output?

NFRisk practitioner interpretation

Control implication

Where system output can trigger financial, disciplinary or legal consequences for a person, reliability must be tested before action is taken. Required evidence includes the relevant error paths, audit trail, independent corroboration, disclosure of known defects and a route for affected users to trigger technical review. Repeated challenges to system output are potential control signals, not merely complaints to be closed.

Framework relevance

Explicitly labelled analytical mappings

NFRisk analytical mapping

COSO ERM lens: Review & Revision

NFRisk maps the Court of Appeal's findings that reported system problems were not adequately investigated or disclosed to COSO's Review & Revision component. This is a retrospective analytical mapping, not a finding made by the court or COSO.

Enterprise Risk Management - Integrating with Strategy and Performance · Committee of Sponsoring Organizations of the Treadway Commission (COSO)

Evidence register

Primary and supporting sources

  1. Court of Appeal (Criminal Division), Judiciary of England and Wales

    Hamilton and Others v Post Office Limited [2021] EWCA Crim 577 (opens in a new tab) 23 April 2021 · Authoritative primary source
  2. UK Parliament / legislation.gov.uk

    Post Office (Horizon System) Offences Act 2024 and Explanatory Notes (opens in a new tab) 24 May 2024 · Authoritative primary source
  3. Scottish Parliament / legislation.gov.uk

    Post Office (Horizon System) Offences (Scotland) Act 2024 (opens in a new tab) 13 June 2024 · Authoritative primary source
  4. UK Department for Business and Trade

    Horizon Convictions Redress Scheme: applying for financial redress (opens in a new tab) 30 July 2024 · Authoritative primary source
  5. COSO

    Enterprise Risk Management - Integrating with Strategy and Performance (opens in a new tab) 1 June 2017 · Authoritative primary source

Publication note

A documented external event—not an NFRisk client engagement.

The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.

Return to the Risk Scenario Library

From scenario to mandate

Test the equivalent control assumption in your environment.

NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.

Start a conversation