An internal fraud investigation in the Netherlands has to satisfy three bodies of law at once: the criminal law that defines the offence, the supervisory law that obliges regulated firms to report, and the employment and data protection law that limits how an employer may gather evidence about its own staff. Getting one of the three wrong usually costs you the other two. Evidence collected in breach of the GDPR is regularly set aside in dismissal proceedings, and a dismissal that fails in court weakens the criminal file that rests on the same material.
Which offences the Criminal Code actually names

There is no single offence called fraud in Dutch law. What is charged depends on the conduct. Forgery of documents, including invoices, contracts and accounting records, is article 225 of the Criminal Code. Embezzlement of goods or money already lawfully in your possession is article 321, and article 322 raises the maximum where the embezzlement is committed by an employee. Deception, the classic act of moving someone to hand over money by a false name, a false capacity or a web of lies, is article 326. Bribery in the private sector is article 328ter, misleading annual accounts is article 336 and bankruptcy fraud is dealt with in the provisions on bankbreuk. Money laundering sits in articles 420bis to 420quater, in the Criminal Code and not, as is often assumed, in the anti-money laundering statute itself.
Those distinctions are not academic. Maximum sentences range from three years for simple embezzlement to eight years for habitual money laundering, and the elements the prosecution must prove differ sharply between them. An accusation described loosely in an internal report as fraud may in fact be a forgery case, in which the document rather than the loss is the centre of gravity. Our guides to fraud under Dutch law and to bankruptcy fraud set out the individual offences in more detail.
The supervisory layer: Wwft, Wft and the authorities involved
Banks, accountants, tax advisers, civil-law notaries, lawyers, estate agents and trust offices fall under the Anti-Money Laundering and Anti-Terrorist Financing Act (Wet ter voorkoming van witwassen en financieren van terrorisme, Wwft). It requires client due diligence before the relationship starts, continuing monitoring of transactions, and the reporting of unusual transactions to FIU-Nederland without delay. The wording matters: an institution reports what is unusual against objective and subjective indicators, and it is FIU-Nederland that decides whether a transaction is designated suspicious and passed on to the investigating services. Breaches of the Wwft are economic offences and can be prosecuted under the Economic Offences Act as well as being punished administratively. The difference between the two concepts is explained in our article on money laundering and unusual transactions.
Alongside that sits the Financial Supervision Act (Wet op het financieel toezicht), which governs licensing and conduct in the financial sector. The Dutch Authority for the Financial Markets supervises conduct and market integrity, while the Dutch Central Bank carries out prudential and integrity supervision; both can give binding instructions and impose penalty payments and administrative fines. Criminal investigation of financial and fiscal offences is largely the work of the Fiscal Information and Investigation Service, which operates under the direction of the specialised division of the Public Prosecution Service. A company under scrutiny is therefore rarely dealing with only one authority, and information moves between them.
Starting an internal fraud investigation without breaking the rules

An employer is entitled to investigate a well-founded suspicion of fraud within its own organisation, but the investigation must be proportionate to what is suspected and it must use the least intrusive means that will do the job. In practice that means starting from a written suspicion and a written investigation plan, defining in advance which systems and which period will be examined, and recording every step taken. Those records are not bureaucracy: when the dismissal or the criminal case is later tested, the file has to show why each measure was necessary at the moment it was taken.
Two formal requirements are easy to overlook. Any arrangement for systems designed to observe or monitor the presence, conduct or performance of staff requires the consent of the works council; introducing monitoring software in the middle of an investigation, without that consent, taints everything it produces. And the processing of personal data in an investigation needs a lawful basis under the GDPR, which for a private employer will normally be legitimate interest, assessed against the employee’s privacy in a documented balancing exercise. Where the monitoring is systematic or large-scale, a data protection impact assessment comes first, not afterwards.
What you may do with email, systems and employee data
Reading an employee’s mailbox is not automatically unlawful, but it is only defensible where the suspicion is concrete, the search is limited in time and search terms, and the employee has been informed in advance, through a policy, that business systems may be inspected in defined circumstances. Blanket screening of private correspondence, covert cameras in the ordinary workplace and open-ended keyword sweeps across years of mail are the measures that fail. Where an investigation report is produced, the employee retains the right of access to their own personal data in it, subject to the rights of others named in the same file, and refusing that access outright tends to be counterproductive.
Hearing the employee is a legal step, not a courtesy. An accusation of fraud has to be put to the person concerned, in a way they can actually respond to, before a decision is taken. Courts read a refusal to allow a proper response as a sign that the investigation was directed at confirming a conclusion already reached. Where an external investigator is engaged, the employer stays responsible for how the investigation is conducted.
Dismissal after fraud: what the employer must prove

Fraud by an employee can justify summary dismissal (ontslag op staande voet), but the bar is high and it has three parts: there must be an urgent cause, the dismissal must be given without delay once the facts are sufficiently clear, and the reason must be communicated immediately and precisely. Employers lose these cases most often on the second element, because they let weeks pass while an investigation runs. The safer route in a complex financial case is often a request to the subdistrict court to dissolve the contract for culpable conduct, which allows the investigation to be completed first. Where the conduct is seriously culpable, the transitional payment can be withheld, and the employer may claim damages; both require the same evidence to hold up. Our article on summary dismissal and what it requires sets out the test, and the wider framework is covered in our guide to Dutch employment law.
Whistleblowers: the reporting channel and the ban on retaliation
Most internal fraud comes to light because somebody inside the organisation says something. The Whistleblower Protection Act (Wet bescherming klokkenluiders), in force since 18 February 2023 and implementing the European whistleblowing directive, obliges employers with at least fifty employees to have an internal reporting procedure; private employers with fifty to two hundred and forty-nine employees had until 17 December 2023 to bring their arrangements into line. The reporter may go to an external authority as well as internally, and anonymity of the reporter must be protected within the procedure.
The sharpest provision for employers is the ban on detriment. A reporter who suffers a disadvantage after making a report is protected, and the burden of proof is reversed: it is for the employer to show that a transfer, a poor appraisal, a suspension or a dismissal had nothing to do with the report. That reversal applies for a considerable time after the report, which is why disciplinary action against someone who has raised a concern needs its own separate, documented justification.
When the criminal and regulatory tracks take over
An internal investigation can end in a settlement and a dismissal, but it can also end in a criminal file. A company can be prosecuted in its own right, and those who directed or knowingly tolerated the conduct can be prosecuted as de facto managers alongside it. Investigators can enter business premises, seize administration and digital data and freeze bank balances, and the Public Prosecution Service can bring a separate claim to recover the estimated proceeds of the offence. Where cash or bank balances are seized, the route to getting them released runs through a complaint procedure rather than through negotiation, as we explain in our article on your rights when money is seized.
Institutions are not too big to be prosecuted. In 2018 ING Bank accepted a settlement of 775 million euros with the Public Prosecution Service over structural shortcomings in its client due diligence and transaction monitoring under the Wwft. The lesson for smaller organisations is not the size of the figure but the reasoning: the failure that was penalised was the compliance system, not a single transaction. Self-reporting, cooperation and demonstrable remediation are relevant to how a case is disposed of, but they are decisions that should be taken with counsel and not in the first hour of a raid.
What to do in the first week
Secure the data before anything else, in a way that preserves the original and its metadata, because the most common evidential problem in these files is a well-meaning manager working in the live system. Limit the circle of people who know, put the investigation under legal privilege where that is possible, and decide early whether a report to a supervisor or to FIU-Nederland is legally required, since that decision has its own deadline and is not suspended by the internal investigation. Do not suspend or confront the employee before the evidential position is clear, and do not promise confidentiality you cannot deliver. If a criminal complaint is being considered, weigh it against the loss of control that follows: once a file is with the investigating services, disclosure is no longer yours to manage. Our overview of compliance obligations for companies in the Netherlands sets out the preventive side of the same problem.
The Dutch approach to fraud and financial crime
Which articles of the Dutch Criminal Code cover fraud, forgery and embezzlement?
There is no single fraud offence. Forgery of documents is article 225, embezzlement is article 321 and embezzlement by an employee article 322, deception is article 326, private bribery is article 328ter and money laundering is covered by articles 420bis to 420quater of the Dutch Criminal Code. Maximum sentences run from three years for simple embezzlement to eight years for habitual money laundering.
What extra obligations does the law against money laundering and terrorist financing place on banks?
The Wwft requires banks, accountants, notaries, lawyers, estate agents and other designated institutions to carry out client due diligence, to monitor transactions continuously and to report unusual transactions to FIU-Nederland without delay. It is FIU-Nederland, not the institution, that decides whether a transaction is designated as suspicious and passed to the investigating services.
What role does the financial supervision act play?
The Financial Supervision Act (Wet op het financieel toezicht) governs licensing and conduct in the financial sector. The Dutch Authority for the Financial Markets supervises conduct and market integrity and the Dutch Central Bank supervises prudential soundness and integrity; both can give binding instructions and impose penalty payments and administrative fines.
Do Dutch authorities work with other countries on financial crime?
Yes. FIU-Nederland exchanges information with other financial intelligence units, the Fiscal Information and Investigation Service cooperates with Europol and Eurojust, and the European Public Prosecutor Office, in which the Netherlands participates, can investigate fraud affecting the EU budget.
Related reading
- Money laundering penalties in the Netherlands
- Suspected of money laundering: what to do and what not to do
- Online fraud and phishing: proving digital deception
- Identity fraud and the sentences it carries
Law & More advises companies, directors and employees on fraud and financial crime, from the first internal signal through the investigation, the dismissal and, where it comes to that, the criminal file. If a suspicion has arisen in your organisation, contact our team in Eindhoven or Amsterdam before the first system is opened, so that the evidence you gather can still be used.


