• via Alberto da Giussano, 26, 20145 Milano
  • +39 02 8295 4969
  • info@studiolegalebianucci.it
Avv. Marco Bianucci
Avv. Marco Bianucci

Criminal Lawyer

A fraudulent client request can create difficulties even for a law-abiding business. The issue is not just figuring out whether the client is acting improperly. You must also decide whether your company can execute the request, whether it is necessary to halt an already initiated process, and how to prevent an employee from turning commercial pressure into a contribution to an unlawful act.

In this guide, I explain which elements distinguish an irregular request from a concrete criminal risk, why not every anomaly amounts to a crime, and which choices help avoid collaborating with fraud. We will also look at the role of internal procedures, the 231 compliance model, and documentation: useful tools when they clarify who decides, based on what data, and with what limits.

When a client request creates a criminal risk

Suspicion is not enough to attribute criminal liability. A client may be confused, provide incomplete information, or request a modification that has a lawful explanation. The business does not become liable simply because it receives an unusual inquiry. The risk grows when the request aims to represent a non-existent fact as true, conceal essential data, or obtain money, authorizations, or other advantages from a third party through deception.

Fraud must be identified in the content of the transaction. For example, an invoice for a service never performed, a declaration certifying absent requirements, or the fictitious backdating of a document are not mere formal irregularities. They can be steps instrumental to a deception directed at a lender, a public entity, an insurer, a supplier, or another party. Article 640 of the Italian Criminal Code governs fraud; the text of the Italian Criminal Code on Normattiva classifies this offense among crimes against property committed through fraud.

Signals must be read as a whole. Artificial urgency, the invitation to use only verbal communications, the request not to involve those who normally approve the act, or insistence on modifying a document after signature are elements to be taken seriously. However, they do not replace fact-finding. The decisive question remains concrete: what act is the client asking for, and what would that act declare or produce toward third parties?

The boundary between ordinary activity and contribution to fraud

One does not need to be the principal offender to assume criminal relevance. Article 110 of the Italian Criminal Code governs the complicity of multiple persons in an offense. In practice, the issue arises when the business did not conceive the operation, but provides a document, a statement, a payment, IT access, or an administrative step useful to the client's project.

Lawful performance remains distinct from knowing collaboration. Issuing a document based on received data does not automatically equate to participating in a wrongdoing committed outside the company. The situation changes if those operating on behalf of the company know that the content is false and nevertheless contribute to drafting it, transmitting it, or making it more credible. Therefore, the information actually available, the communications received, and the concrete utility of the requested activity matter.

A client order does not make the requested act lawful. Those receiving commercial instructions may have limited margins, but must not execute a step that requires certifying unverified facts or facts contrary to data already present. At the same time, it is not useful to turn every discrepancy into an accusation. A correct response separates the fact to be proven from the hypothesis: verifiable feedback is requested, or the act that cannot be performed is refused.

Stopping, clarifying, or refusing the request

The first choice is to stop the risky act. If the client asks for an untruthful statement, a fictitious invoice, an unfounded retroactive modification, or the sending of false data, the company must not execute that step. There is no need to immediately formulate a criminal accusation: it is sufficient to communicate that the activity cannot be carried out with that content or in the absence of the required prerequisites.

Suspension serves when an avoidable doubt exists. It may happen that a service was actually performed, but a formalized order is missing; or that a modification is lawful, but requires the written consent of the counterpart. In these cases, the matter can remain suspended until the necessary document is produced. If the client provides coherent elements, the company can proceed within the limits of the ascertained facts. If instead they ask to move forward without feedback, suspension must give way to refusal.

Correction must make the document true. Changing a draft to correct an error, integrating missing data, or describing a service actually performed is different from seeking a less explicit formula to represent a non-existent fact as regular. Neutral language does not eliminate the risk if the document continues to communicate false or misleading information to the recipient.

The relationship with the client must not be handled through automatisms. Stopping a specific practice does not always require interrupting every contract. It is necessary to understand whether other services are autonomous and lawful, whether the contract allows for suspension or termination, and whether the trust necessary for the relationship is now compromised. The mistake to avoid is proceeding by inertia solely on the problematic operation, relying on the fact that the initiative came from the client.

Internal procedures that reduce ambiguities

A useful procedure indicates who can decide. In processes that produce invoices, contracts, refunds, payments, declarations, or practices intended for third parties, whoever receives an anomalous request must know whom to forward it to. Escalation is not an empty bureaucratic step: it prevents a delicate decision from being left to haste, purely commercial relationships, or the fear of losing the client.

Controls must concern decisive facts. A rule may require that changes to bank details be confirmed through an independent channel, that a contractual modification be in writing, or that a tax document correspond to an order and a traceable service. Control must be proportional to the service and the possible loss. Demanding checks extraneous to the relationship is useless; neglecting the data that makes the operation credible toward third parties is risky.

Traceability documents a correct choice. Retaining the request, communications, produced documents, and the decision made allows for reconstructing why the company suspended, refused, or proceeded with a practice. This does not mean creating an accusatory dossier on the client. It means preventing a sensitive step from being entrusted to informal conversations, uncertain memories, or versions prepared only after the problem has emerged.

Compliance Model 231 and reporting channels: limits and utility

Compliance Model 231 is not an automatic shield. Legislative Decree no. 231 of 2001 governs entity liability for certain offenses committed in their interest or advantage by persons holding senior positions or persons subject to their direction or supervision. Not every wrongdoing attributed to a client or a person operating within the company automatically transfers liability to the company. The regulatory framework is found in Legislative Decree no. 231 of 2001 published on Normattiva.

The model is useful if it guides real behavior. Protocols must explain, for exposed activities, which data cannot be altered, who authorizes an exception, what verification must be carried out, and how to interrupt a risky flow. A generic text against fraud does not resolve the request arriving at the commercial, administrative, or operational office. A comprehensible rule is needed precisely at the point where a person may be induced to perform an improper act.

The internal channel does not concern every commercial dispute. Legislative Decree no. 24 of 2023 governs the protection of persons who report certain violations learned in a work context. The obligation to activate internal channels depends on the subjects involved and the prerequisites set by the law; these include, under specific conditions, private entities with at least fifty workers or subjects adopting a 231 compliance model. Legislative Decree no. 24 of 2023 distinguishes the scope of reports from requests related to an exclusively personal interest.

If the request has already arrived or someone has already acted

It is necessary to prevent the practice from proceeding by inertia. If a request appears to require sending false data, an unjustified payment, or an untruthful declaration, the first point is to block the concrete act still capable of execution. This does not necessarily equate to paralyzing every relationship with the client, but it prevents the company from adding its own contribution to the event.

Existing documents must not be rewritten. Emails, messages, drafts, attachments, and internal records can clarify what was requested, who replied, and whether someone has already performed an operational step. Deletions, retroactive modifications, or communications constructed solely to appear diligent can aggravate uncertainty rather than resolve it. The subsequent response must remain consistent with what the company truly knows.

Sector and role can change obligations. Some activities are subject to specific rules of control, retention, or reporting; others primarily require refusing the improper act and correctly reconstructing the company's position. For targeted comparison, the request received, involved documents, previous communications, and applicable procedures are useful: they allow distinguishing what was asked from what was actually done.

Frequently Asked Questions

Can I refuse a request without accusing the client of a crime?

Yes, you can refuse the specific act. If the request forces you to declare an unverified fact, issue an untruthful document, or bypass an internal rule, it is sufficient to communicate that the company cannot proceed on those terms. Operational refusal does not require formulating a criminal accusation, which presupposes a different and broader investigation.

Does an employee take risks if they execute an order received from the client?

The client's order does not eliminate the problem. The relevance of the conduct depends on the content of the act, the available information, and the actual contribution made to the event. If the instruction requires falsehoods, intentional omissions, or the bypassing of controls, the employee must halt the step and use the decision-making channel provided by the company.

Must I immediately sever all relationships with a suspicious client?

Not necessarily. You must first prevent the operation presenting the risk. Other services may continue only if they are genuinely autonomous, lawful, and compatible with the contract. If the fraudulent request shows that the relationship is founded precisely on collaboration in deceptive conduct, terminating the relationship can become a concrete option to consider.

Does a 231 compliance model prevent company liability?

No, it is not an automatic guarantee. The model can assume relevance under the conditions provided by Legislative Decree no. 231 of 2001, but it must be suited to the risk and implemented effectively. It does not replace the verification of what happened, nor does it render irrelevant knowing conduct carried out by those operating in the entity's interest or advantage.

Must I retain communications that seem suspicious to me?

Yes, retaining them without alterations is prudent. Messages, emails, drafts, and attachments can show what request arrived, how the company responded, and whether the matter was suspended. Retention must respect company rules on confidentiality and data access; it does not require distributing the material to those not participating in the decision.

A comparison before performing the requested act

Acting beforehand prevents an improper request from becoming a fait accompli. If you need to respond to a client, suspend a practice, or clarify internal responsibilities after an activity has already been carried out, you can contact me with the essential communications and documents. Together with my staff, I can help you distinguish a correctable irregularity from a step that must not be executed.