

A foreign company discovers suspected employee fraud in Turkey. Learn how to preserve emails, accounting records, bank transfers, company devices, CCTV and digital evidence before filing a criminal complaint.
When a foreign-owned company discovers suspected employee fraud in Turkey, the first reaction is often to dismiss the employee immediately and file a criminal complaint. However, acting too quickly without preserving evidence can seriously weaken the investigation. Emails may be deleted, company devices may be wiped, accounting records may be altered, passwords may change, CCTV recordings may be overwritten and money may be transferred to additional accounts. Before filing a criminal complaint, the company should therefore establish a controlled evidence-preservation and internal-investigation process while avoiding unlawful access to private communications or improper manipulation of digital evidence.
Employee fraud can involve unauthorized money transfers, fictitious invoices, false expense claims, manipulation of company accounts, diversion of customer payments, unauthorized discounts, supplier kickbacks, inventory theft, misuse of corporate credit cards, forged signatures, false contracts or transfers to related persons or companies.
The precise criminal characterization depends on the facts.
One of the most common mistakes is confronting the suspected employee before securing company records. Once the employee learns about the investigation, evidence may disappear.
The company should first identify which records and systems require immediate preservation.
Documents and electronic records should be preserved in their original form wherever possible. Investigators may later need to determine when a document was created, modified or transmitted.
A rewritten spreadsheet or screenshot alone may be weaker than the underlying original record.
If the suspected employee uses a company-owned computer, preserve the device and prevent unnecessary changes to its data.
Avoid allowing multiple employees to search through the computer informally.
For serious allegations, a forensic copy of a company device may help preserve data in a manner suitable for later technical examination.
The process should be documented carefully so that the integrity of the evidence can later be explained.
Do not immediately delete or deactivate the employee’s account in a way that destroys stored data.
Preserve relevant emails, attachments, account logs and other company-controlled information before changing access rights.
Modern companies often store important evidence in cloud-based accounting, CRM, document-management and communication systems.
Preserve relevant records before retention policies or automated deletion remove them.
Export relevant ledger entries, journal records, invoices, payment records, expense reports and transaction histories.
Where possible, preserve both the accounting-system data and the underlying source documents.
Suspected fraud frequently involves bank transfers. Identify the company accounts affected and preserve payment instructions, account statements, approval records and transaction details.
Determine who initiated and approved each transaction.
Compare suspicious payments with the employee’s actual corporate authority.
Internal authorization policies, signature circulars, powers of attorney and banking mandates can help establish whether the transaction exceeded the employee’s authority.
Where fictitious or inflated invoices are suspected, preserve the original invoice, purchase order, delivery documentation, approval records and payment information.
Determine whether the supplier actually provided the goods or services.
Check whether suspicious suppliers are connected with the employee, relatives, former employees or other related persons.
Corporate registry and payment information may become relevant to the investigation.
Many accounting and enterprise systems record which user created, approved, changed or deleted a transaction.
These audit trails can be extremely valuable and should be preserved before system maintenance or account deletion affects them.
Screenshots can be useful, but they should generally supplement rather than replace original electronic records.
Where possible, preserve the complete file, message, metadata and system records associated with the evidence.
Business communications through corporate messaging systems may contain relevant evidence. However, companies should distinguish between corporate records and genuinely private communications.
Unlawful access to an employee’s private accounts can create separate legal problems.
The fact that an employee is suspected of fraud does not automatically give the employer unrestricted access to personal email, social-media accounts, private cloud storage or personal devices.
Evidence collection should respect privacy, data-protection and criminal-procedure requirements.
A company-owned mobile phone may contain both business and personal information. Preserve the device without unnecessarily examining unrelated private content.
For serious cases, technical examination may be more appropriately conducted through formal investigative procedures.
CCTV systems frequently overwrite recordings automatically after a limited period.
If footage may show meetings, document removal, warehouse access or other relevant conduct, preserve the relevant period immediately.
Exporting a short video clip may not be enough. Preserve the original recording or a technically reliable copy together with information identifying the camera, date and time.
Incorrect system clocks can create confusion. Document whether the CCTV timestamp corresponds accurately with real time.
Secure contracts, invoices, signed payment instructions, receipts, notebooks and other physical records relevant to the suspected conduct.
Maintain a record of who collected and stored them.
For important evidence, record who obtained it, when it was obtained, where it was stored and who subsequently accessed it.
This is especially important for computers, phones, storage devices and original documents.
Internal fraud allegations should normally be shared only with personnel who need to know.
Uncontrolled circulation can alert suspects, compromise evidence and create unnecessary employment or privacy disputes.
Prepare a timeline showing suspicious transactions, approvals, communications, meetings and discoveries.
A clear chronology can significantly assist prosecutors in understanding a complex corporate fraud complaint.
Do not assume immediately that only one employee was involved.
Review approval chains, account access, supplier relationships and payment destinations to determine whether other employees or external parties may have participated.
Employees who processed invoices, approved transactions, communicated with suppliers or discovered irregularities may become witnesses.
Record what each person actually knows without coaching them to provide a particular version.
If employees reported suspicious conduct by email or through internal compliance channels, preserve those reports.
Contemporaneous reports can help establish when the company first became aware of the suspected fraud.
Witnesses should not be encouraged to agree on a common narrative.
Their independent recollections are generally more valuable than statements shaped by group discussions.
Where internal interviews are appropriate, record the date, participants and issues discussed.
The interviewer should distinguish between facts personally observed by the employee and information learned from others.
Pressure, threats or improper promises can create legal and evidentiary problems.
The objective of the internal investigation should be preservation and clarification of facts, not obtaining a predetermined confession.
Determine whether the employee had authority to make the disputed transaction.
Fraud cases can become complicated where the employee technically possessed broad corporate authority but allegedly used that authority for an improper purpose.
If forged signatures are suspected, preserve original documents containing both disputed and genuine signatures.
Originals may become important for expert examination.
If transactions were approved electronically, preserve authentication records, timestamps, IP information where lawfully available and approval logs.
The investigation should identify how the company’s authorization system actually operated.
Create a transaction map showing the amount, date, originating company account, recipient account, stated purpose and supporting document.
Where several transfers are involved, a visual chronology can help identify patterns.
Provide prosecutors with accurate available information concerning the accounts receiving suspected fraudulent transfers.
Banking information can become important when requesting investigative measures.
The criminal complaint should not focus solely on misconduct. Document the financial damage.
Preserve bank records, accounting entries, replacement costs, unpaid customer balances and other evidence showing the company’s actual loss.
Internal reports should separate confirmed facts from allegations and assumptions.
For example, “payment was transferred to Company X” is different from “Company X belongs to the employee,” unless the relationship has actually been established.
A credible internal investigation should preserve relevant evidence even if it does not support the company’s initial theory.
Selective evidence preservation can damage the reliability of the complaint.
If substantial money has recently been transferred and there is a risk of dissipation, the company should obtain immediate legal advice concerning possible criminal and civil protective measures.
Speed can be critical where funds are moving between accounts.
A criminal investigation may determine criminal responsibility, but recovery of the company’s financial loss may also require separate civil, commercial, employment or enforcement measures.
The company should develop both strategies together.
Discovery of suspected fraud may also raise employment-law issues. The company should preserve the evidence supporting any disciplinary or termination decision and observe applicable employment-law requirements.
A criminal complaint does not automatically determine the validity of an employment termination.
Employment and criminal proceedings can follow different evidentiary and procedural paths.
Relevant employment records should therefore be secured immediately.
A strong complaint should explain what happened, when it happened, who was involved, how the conduct was discovered, what evidence supports each allegation and what financial loss resulted.
Large quantities of documents should be organized rather than submitted without explanation.
If emails, accounting logs or digital files are central to the allegation, explain their source and relevance.
The prosecutor should be able to understand why each digital record matters.
Depending on the facts, investigative steps may concern banking records, digital examination, witness statements, company records or other evidence that the company cannot obtain itself.
Requests should be proportionate and connected to the suspected offense.
A foreign parent company may hold relevant approval emails, audit reports, compliance communications or financial records outside Turkey.
These materials should be preserved as soon as the fraud is discovered.
Documents submitted in a Turkish criminal proceeding may require proper translation.
Accounting terminology and technical corporate language should be translated accurately so that the evidentiary meaning is not changed.
A multinational company should determine which entity suffered the loss, which entity employed the suspect and which entity owns the relevant records.
This distinction can affect both the criminal complaint and later compensation claims.
If the suspected employee held a corporate power of attorney, determine whether it should be revoked immediately.
Banks, customers and business partners may also need to be informed where legally and commercially appropriate.
Where the employee has online banking authority, review access immediately and consider changing corporate permissions.
Preserve the existing authorization records before making changes.
Access rights may need to be suspended to prevent deletion or manipulation of records.
However, preserve logs showing the employee’s historical access before changing the account.
Crime, fidelity, cyber or other corporate insurance may potentially respond depending on policy wording.
Any notification requirements should be reviewed promptly.
Major mistakes include confronting the employee before securing evidence, wiping the employee’s computer, deleting the corporate email account, relying only on screenshots, accessing private accounts without legal authority, failing to preserve CCTV, altering original spreadsheets and submitting thousands of unexplained documents to prosecutors.
A foreign company discovering suspected employee fraud in Turkey should immediately secure company devices, preserve corporate emails and cloud records, export accounting and ERP audit trails, preserve bank and payment records, secure CCTV footage, collect original contracts and invoices, document access and chain of custody, restrict investigation information, prepare a transaction chronology, identify witnesses, trace suspicious payments, preserve evidence of financial loss and coordinate criminal, employment and asset-recovery strategies before confronting the suspected employee.
Usually the company should first consider whether important evidence could be deleted, altered or removed and preserve relevant records before confrontation.
Company-controlled devices may contain relevant corporate evidence, but privacy, data-protection and proportionality considerations should be evaluated. Unrestricted examination of unrelated private material should be avoided.
They can be useful, but original electronic records, metadata, system logs and source files can provide significantly stronger evidentiary context.
Yes, where relevant. Many systems automatically overwrite older recordings.
The employer should not assume that suspected fraud creates unrestricted authority to access private accounts. Evidence should be collected through lawful means.
Company-held banking records can be important, while prosecutors may obtain additional banking evidence through formal investigative mechanisms where legally justified.
Employment termination requires a separate legal assessment. Evidence should be preserved and employment-law deadlines and requirements should be considered independently.
Depending on the facts and legal requirements, urgent protective measures may potentially be available. Cases involving rapidly moving funds should be evaluated immediately.
Yes. Relevant emails, audit reports, approvals, accounting information and compliance records held abroad should be preserved.
Preserve the original evidence before alerting the suspected employee. Secure corporate emails, accounting records, bank transactions, devices, system logs and CCTV in a documented manner so that the evidence remains available and its integrity can later be explained to Turkish prosecutors and courts.
Employee fraud involving a foreign-owned company can require simultaneous criminal investigation, digital evidence preservation, bank tracing, asset-protection measures, employment action and civil recovery proceedings. Fırat Fesih Kaya Law Office assists foreign companies, international investors and Turkish subsidiaries in internal fraud investigations and criminal complaints in Turkey. Lawyer Fırat Fesih Kaya provides legal assistance in preserving evidence, preparing criminal complaints, coordinating digital and financial records, protecting company assets and pursuing legal remedies against employees and third parties involved in suspected fraud.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower, Office No:148, 06520 Balgat, Çankaya, Ankara, Turkey