Summary

  • A distressed-business function carries exceptional power. A bank deciding that a customer is impaired can control credit, cash, security enforcement, professional appointments and whether the business has time to recover. That concentration of power requires conflict checks, independent credit challenge, transparent consultant selection, direct complaint escalation and evidence showing that every fee and decision advances a legitimate restructuring objective.

  • The criminal convictions were actor-specific. Six people were convicted for offences connected with the Reading fraud, including two former Bank of Scotland employees and private business advisers. The final records describe different roles, offences and sentences. They do not make every employee, consultant or customer part of the crime, and they did not criminally convict Bank of Scotland, HBOS or Lloyds.

  • The 2019 FCA penalty addressed regulatory disclosure, not participation in the fraud. The FCA fined Bank of Scotland GBP45.5 million for failing to be open and cooperative and failing to disclose information appropriately after suspicions emerged. The legal findings concerned Principle 11 and notification duties. The regulator did not convict the bank of committing the underlying fraud and stated that commercial lending was largely outside its conduct jurisdiction.

  • The warnings problem was organisational. Internal information referred to suspicious conduct and the “Reading fraud,” yet the full picture was not provided to the regulator until July 2009. The FCA found limited public evidence challenge, scrutiny and inquiry across the organisation rather than attributing the disclosure failure to one person. That is a governance lesson about who must assemble fragmented evidence and decide when suspicion becomes a reportable matter.

  • The first customer review could not define fairness by acceptance rates alone. Lloyds established a voluntary review overseen by Professor Russel Griggs. Customers received outcomes and many accepted offers, but acceptance under financial pressure does not independently validate the population, methodology or loss calculation. A remedy must show how direct loss, consequential loss, distress, debt relief and the position of directors were assessed.

  • Cranston identified serious shortcomings but did not invalidate every award. Sir Ross Cranston's independent assurance review found defects in important aspects of the Griggs methodology and process, including treatment of direct and consequential losses, eligibility and consistency. It recommended a re-review, wider approaches to debt relief and de facto directors, and more independent decision-making. Those findings do not mean every original outcome was wrong.

  • Foskett and Dobbs are different reviews with different current statuses. The Foskett Panel re-reviews compensation through an independent, non-court process using a lower evidential basis and a stated generous, fair and common-sense approach. By the 2025 reporting date, the whole identified population had an initial decision, while a small number of challenges remained. The separate Dobbs Review concerns what Lloyds knew or should have known after acquiring HBOS and whether matters were properly investigated and reported. It remained unpublished on 19 July 2026.

  • Provision, offer, award, confiscation and recovery are not synonyms. Accounting provisions can include compensation, tax, lawyers, panel operations and the Dobbs Review. Criminal-benefit assessments and confiscation orders depend on available assets. Offers may be accepted or challenged. Cash reaching victims is a separate measure. Accountability requires a dated measurement dictionary rather than one large, blended number.

Distressed-business control is a fiduciary-style accountability test

An impaired-assets unit operates where a bank customer has the least bargaining power. A company may be short of cash, in covenant breach or dependent on continued facilities to pay wages and suppliers. The bank can require information, restrict payments, alter credit limits, appoint advisers, demand security or begin enforcement. These rights arise from contract and legitimate risk management, but their concentration creates an obligation for strong institutional challenge.

The first control is an independently evidenced transfer into impaired-assets management. The file should show the financial trigger, covenant position, customer representations, alternatives considered and authority for the decision. The relationship manager should not be able to classify a customer, select the turnaround adviser, approve new money and judge the adviser's success without review. Each stage needs a separate owner and a recorded route for challenge.

Consultant selection is especially sensitive. A distressed customer may feel it has no practical choice when a bank insists on a particular adviser. The bank should maintain an approved panel based on competence, conflicts, fees and outcomes, but should also permit justified customer alternatives. Any social, financial or prior business relationship between bank staff and an adviser must be declared, independently tested and, where appropriate, disqualifying. Gifts, hospitality or payments require surveillance that looks across employee, family and connected-company data.

Credit decisions need a dual record: why additional lending could preserve value and where the money would go. New facilities can be appropriate if they fund working capital or a credible turnaround. They can deepen harm if fees, asset transfers or unrealistic plans consume the proceeds. Approval should therefore reconcile cash-flow forecasts, adviser fees, milestones, security, valuation and downside recovery. A manager's delegated authority must be enforced by systems, not merely written in a manual.

The final control is a complaint route independent of the team being challenged. Business owners must be able to raise concerns about coercion, conflicts, fees or document accuracy without the complaint returning to the same decision-maker. Serious allegations should reach legal, financial-crime and board-risk functions, with a decision about police and regulator reporting. The issue is not whether every complaint is substantiated. It is whether the institution can recognise when several accounts, unusual payments and control breaches form a credible suspicion.

The criminal record must remain actor-specific

The 2017 convictions gave the case its public trigger, but precision about each actor is essential. The FCA's Final Notice for Lynden Scourfield records his role as Director for London and South of England in the impaired-assets operation, his guilty plea to conspiracy to corrupt and fraudulent trading, his sentence and the later financial-services prohibition. The notice concerns Scourfield. It does not establish misconduct by every manager in his reporting chain or every customer file he handled.

The Final Notice for Mark Dobson records a different role and criminal outcome. Dobson had worked as an associate director and was convicted of conspiracy to corrupt. His notice supports statements about his own conduct, sentence and prohibition. It should not be merged with Scourfield's plea, authorities or portfolio as though the two records were identical.

The private-adviser side also requires separation. The Final Notice for Alison Mary Mills and the separate Final Notice for David Mills state the offences, convictions and prohibitions applying to each person. Similar surnames and connected business activity do not permit findings to be transferred between them. A source ledger should preserve the actor, charge, verdict, sentence, confiscation position and regulator action for each record.

The convictions established serious crimes involving bank insiders and connected advisers. They did not criminally convict Bank of Scotland, HBOS or Lloyds Banking Group. Corporate responsibility can still arise through regulatory duties, civil claims, governance findings, customer remedy and the conduct of named individuals. Those routes have different legal tests. Saying that “the bank was convicted of fraud” would collapse them and overstate the criminal judgment.

Nor should the criminal record be expanded to every distressed business. The prosecuted case had a defined evidential and charging scope. Other customers may allege related harm, but an allegation becomes an established fact only through an appropriate finding or an expressly identified redress determination. Population design for compensation may deliberately use a broader and lower evidential threshold than criminal prosecution. That policy choice does not retroactively make every eligible case part of the conviction.

Confiscation adds another measurement boundary. A court may assess criminal benefit at one amount and order payment based on available assets or other legal rules. Money recovered by the state, money directed as compensation and amounts later paid through a bank scheme are not interchangeable. A large benefit assessment does not prove that the same sum was available or reached victims.

Bank of Scotland's disclosure failure

The most detailed institutional regulatory record is the FCA's 2019 Bank of Scotland Final Notice. It imposed a GBP45.5 million penalty for contraventions between 3 May 2007 and 16 January 2009. The FCA found that the bank failed to be open and cooperative and failed to disclose information appropriately about suspicions that fraud may have taken place within the Reading-based impaired-assets office.

The distinction between suspicion and proof was central. Bank of Scotland did not possess in 2007 all the evidence that later supported the convictions. It did, however, possess information that raised suspicions. Internal reports used the phrase “Reading fraud,” unusual relationships and payments had been identified, and the regulator had asked to be informed of possible fraud. The FCA found that communications did not provide the full picture and that the internal investigation report was not disclosed until July 2009.

The FCA enforcement summary explains the consequence: delayed scrutiny by the regulator and police risked prejudice to the interests of justice and delayed attention to compensation. It also records that the bank settled early and received a 30 percent discount; without it, the penalty would have been GBP65 million. The Final Notice controls the exact legal scope.

This was not a finding that Bank of Scotland had been criminally involved in the underlying fraud. It was a regulatory finding about Principle 11 and notification obligations. The FCA also stated that commercial lending was and remained largely unregulated, meaning the conduct-of-business and complaints rules at issue in ordinary retail cases did not apply to the underlying lending. The regulator expressly made no merits finding about whether every affected customer's complaint had been assessed appropriately.

The organisational lesson is that a reportable suspicion may emerge from several incomplete records. Financial crime sees unusual payments. Human resources sees an employee matter. Credit sees authority breaches and losses. Complaints sees similar customer allegations. Legal sees uncertainty about privilege or proof. If each function asks whether its own evidence conclusively proves fraud, nobody may assemble the report required by a duty based on awareness of a significant possible fraud.

A sound escalation framework should define triggers below criminal proof. It should identify who owns the combined assessment, which facts are known, what remains disputed, what the regulator would reasonably expect, whether police reporting is required and how customer harm is contained. The decision and dissent should be minuted. A lack of certainty can affect wording, but it should not become a reason to withhold the existence of credible suspicion.

Earlier corporate-control findings were broader than Reading disclosure

The 2019 notice should not be confused with the earlier 2012 Final Notice for Bank of Scotland. The earlier action concerned failures in the wider Corporate Banking Division's organisation and control, including the management of high-risk lending and impairment. Reading illustrated aspects of that control environment, but the notice had a broader entity, period and prudential context than the later disclosure enforcement.

This distinction matters for root-cause analysis. A failure to notify the regulator can be repaired with reporting rules and escalation, but the underlying operating environment may also require changes to credit authority, portfolio concentration, valuation, management information and board challenge. Conversely, broad corporate-risk failings do not prove that every loan decision involved corruption or that every loss was caused by the Reading fraud.

An impaired-assets unit should be reviewed as a portfolio, not only one case at a time. Management information should show migrations into the unit, additional lending, write-offs, fees to external advisers, time to exit, insolvency outcomes, customer complaints, overrides and exposure by relationship manager. Unusual concentrations around one consultant, rapid growth in facilities, repeated exceptions or asset sales to connected parties should trigger investigation.

Audit and risk teams need direct access to source evidence. A summary prepared by the business cannot be the only record of its own exceptions. Reviewers should sample emails, payments, authority logs, consultant contracts, customer communications, valuations and board escalation. Findings should be tracked across human resources, fraud, legal and credit rather than closed within separate taxonomies.

The board should receive bad news without dilution. A report that describes a possible fraud only as a “control weakness” may be technically cautious but operationally misleading. Reporting templates should state both the confirmed control breach and the unresolved suspicion, the amount exposed, affected customers, investigative status and reporting decision. Senior committees should record whether they sought independent advice and whether the issue changed customer handling.

The Griggs review: an internal remedy needed external proof

After the convictions, Lloyds Banking Group established a voluntary customer review overseen by Professor Russel Griggs. The FCA had limited power over the underlying commercial lending, so the bank's willingness to create a remedy was significant. But a bank-funded process assessing harm caused within a predecessor business carries an inherent independence challenge, even when the reviewer is personally independent.

Professor Griggs's letter to the Treasury Committee provides a contemporaneous account of the review, its engagement with customers and settlement progress. It is useful evidence of what the original process said it was doing. It is also a reviewer self-description that later had to be tested against the Cranston assurance review.

Fairness begins with population identification. The review must decide which businesses, directors and related individuals fall within scope. A narrow rule based only on names appearing in the criminal case can exclude customers who present credible evidence of similar conduct. A boundless rule can include ordinary credit losses unrelated to fraud. The methodology should publish the indicators, evidence threshold, reasons for inclusion or exclusion and appeal route.

Loss assessment is equally complex. Direct loss might include fees, diverted money, asset value or additional borrowing. Consequential loss can involve business profits, financing costs, insolvency consequences, lost opportunities and tax. Distress and inconvenience are different again. Some businesses were already financially troubled, so the counterfactual cannot assume perfect success. It must ask what probably would have happened without the misconduct, explain assumptions and disclose uncertainty.

Offer acceptance is not a quality metric by itself. Customers who have waited years, lost businesses or face debt may accept an offer they regard as inadequate because the alternative is more delay and cost. A waiver can conclude a private dispute without proving the methodology was fair across the population. Independent assurance must therefore test files, calculations, exclusions, legal advice, communications and consistency, not merely count settlements.

The review should also separate remedy from narrative control. A customer should not need to agree with the bank's account of events to receive an independently assessed payment. Confidentiality may protect personal or commercially sensitive material, but it should not prevent aggregate scrutiny of methodology, outcomes and recurring control failures. Reasons should be sufficiently detailed for a customer to challenge the decision.

Cranston: serious methodology defects, not a universal nullification

Sir Ross Cranston's independent assurance report examined whether the Griggs Review methodology could deliver fair and reasonable outcomes, whether it was consistently applied and whether the reviewer could properly perform his role. It found serious shortcomings in important aspects, including the assessment of direct and consequential losses, exclusions from the review and inconsistent treatment of distress and inconvenience.

Cranston's findings changed the remedy architecture. Recommendations included independent reassessment of direct and consequential loss, reconsideration of eligibility for debt relief, a wider approach to de facto directors and mechanisms for appeal or reconsideration. The report demonstrated that a process can be well resourced and produce many accepted outcomes while still failing critical tests of scope, methodology and independence.

The FCA's response to the Cranston Review said customers had not yet been properly remediated and that the serious flaws needed to be addressed quickly. It required Lloyds senior management to explain how the failings arose and said it would ensure implementation. At the same time, the FCA's jurisdiction over the underlying unregulated lending and individual awards remained limited. Regulatory pressure for a better process is not the same as the regulator calculating compensation itself.

The Cranston Review project site preserves the review's provenance, original report, later clarification and recommendations for the re-review panel. Later clarification should be dated and distinguished from the original findings. A clarification about debt relief or appeal mechanics may shape implementation without changing every conclusion in the original report.

It would be wrong to infer that every Griggs award was incorrect. Cranston found defects capable of producing unfair or inconsistent outcomes and recommended a new process. Some original calculations may have been reasonable; some customers may have received appropriate sums. The purpose of re-review is to test cases under a corrected methodology, not assume the opposite result automatically.

The independence lesson has several parts. The decision-maker should not report to the bank function defending prior decisions. Experts should be instructed by the panel, not filtered through the bank. Customers should see and answer material evidence. Methodology changes should be published and applied consistently. Quality assurance should sample both awards and exclusions. Appeals should go to a genuinely separate decision-maker with power to change the outcome.

Foskett re-review: initial decisions were not final completion

The Foskett Panel was created to carry out the independent re-review recommended after Cranston. Its stated approach was non-legalistic and intended to decide cases generously, fairly and with common sense, applying an expanded fraud definition and a lower evidential basis than a court. That lower threshold is suitable for a voluntary remediation process but means the panel's decisions are not judicial findings or criminal verdicts.

The most current audited description in the frozen evidence is the Lloyds Bank plc Annual Report 2025. It states that the whole identified population had received an initial decision and that a small number of challenges to initial decisions remained in progress through the published process. It also says there was no confirmed timeline for completion of the re-review or the separate Dobbs Review.

“Initial decision” must therefore not be translated into “settled.” A entity may accept, challenge or continue through another stage. Payment may occur at a different time. Some issues may be final while others remain open. The population itself reflects eligibility decisions that can be contested. A complete status report should show initial decisions, accepted outcomes, challenges, final determinations, payments and unresolved eligibility questions separately.

The panel also offered a fixed-sum route as an alternative to full re-review for people deemed victims under its process. That can deliver speed and certainty, but acceptance of a fixed sum does not validate the counterfactual calculation that a full review might have produced. Public reporting should distinguish fixed-sum outcomes from individually assessed direct and consequential loss awards.

Independence requires operational evidence. The panel should control experts, hearing opportunities, information requests and reasons. The bank can supply records and fund the process without controlling findings. Case-management data should be auditable, and repeated methodology questions should produce published guidance. A challenge process should reveal whether the panel is correcting inconsistency rather than defending its first view.

The House of Commons Treasury Committee's Economic Crime: Consumer View placed the Reading case within the broader challenge of investigating complex fraud and recorded dated compensation measures. Those historical figures illuminate scale and delay but are not final totals. Later re-review provisions, offers and payments use different populations and definitions.

Dobbs: knowledge and reporting remain an unfinished question

The Dobbs Review is separate from compensation reassessment. It was established to consider what Lloyds Banking Group knew or should have known about HBOS Reading after acquiring HBOS in 2009, whether the issues were properly investigated and whether they were appropriately reported to authorities through 2017. It can examine earlier evidence to assess what should have been understood at acquisition, but its principal mandate concerns post-acquisition handling.

The official written parliamentary answer of 19 March 2025 states that the Review began in April 2017, had originally been expected by the end of 2020, was then expected in 2025 and had no planned interim report. The expected 2025 completion was not achieved. An old deadline must not be repeated as if it remained current.

In the House of Lords exchange of 26 March 2026, the minister said drafting was under way and that findings would be shared with the FCA when completed. The exchange also described the Foskett process as having settled the majority of cases while a few remained outstanding. A ministerial status statement is not a final panel certification and should not be used to declare either process complete.

Lloyds Banking Group's current HBOS Reading accountability page, updated 12 May 2026, says the Group must avoid prejudicing Dame Linda Dobbs's work while awaiting the full findings. It sets out the company's account of engagement after the acquisition and its reflections on institutional lessons. Because it is corporate self-reporting about conduct under review, independent findings must control once the report is published.

As of 19 July 2026, the Dobbs Review remained unpublished in the frozen official record. It would be improper to predict whether it will find concealment, adequate reporting, individual fault or any other conclusion. Parliamentary allegations and victim accounts can be reported with attribution, but they do not become Dobbs findings before publication.

The 2020 Commons debate on Lloyds, HBOS and the Cranston Review captures concerns about delay, scope, independence and the experience of affected businesses. Parliamentary speech is important accountability evidence and can identify questions an inquiry should answer. Allegations, estimates and characterisations made in debate must remain attributed unless corroborated by a final primary finding.

When Dobbs is published, readers will need an actor-and-period matrix. It should distinguish HBOS knowledge before acquisition, Bank of Scotland's 2007-2009 disclosure duties, Lloyds actions after acquisition, police investigation, FCA enforcement, customer reviews and later board decisions. Publication status, redactions, privilege and any response from the FCA should be recorded separately. The report should not be used to rewrite the scope of the six criminal convictions.

Accounting provisions and compensation measures need a dictionary

The financial scale of remediation is often described through provisions, but an accounting provision is not a direct payment to victims. It is an estimate of a probable outflow under accounting rules and can include future awards, tax effects, lawyers, panel operations, document review, administration and the Dobbs Review. It changes as information and assumptions change.

The audited annual report therefore supplies evidence of management's estimate and process status, not an admission that every pound represents customer loss. The final outcome can be higher or lower. Utilisation of a provision can include operating expenditure as well as awards. Reports from Lloyds Bank, HBOS and the consolidated group may describe overlapping obligations and must not be added as though they were separate pots.

Compensation “offered” differs from compensation paid. An accepted settlement differs from a challenged initial decision. Debt written off differs from cash transferred. Tax treatment can affect both the payer's cost and the recipient's outcome. Distress awards, direct loss and consequential loss have different methodologies. Reporting should state the population and date for each measure.

Criminal confiscation operates through another legal route. Benefit assessed from crime can exceed assets available for an order. Sums collected under confiscation do not automatically equal money returned to victims. Civil recovery, bank compensation and insolvency distributions can overlap in the harm they address while following separate rules. A measurement table should identify gross amount, payer, recipient population, legal basis, deductions, assigned rights and cash status.

The reason for this precision is not bookkeeping formalism. Large blended figures can create two opposite errors: overstating repair by treating provisions as paid compensation, or overstating unrecovered harm by ignoring settlements, debt relief and other payments. Claimant-level reconciliation is necessary before stating a net total.

A control architecture for impaired-assets accountability

The first layer is customer transfer governance. Entry to an impaired-assets unit should require documented criteria, independent approval and a customer explanation. The file should record alternatives, credit rationale and how the decision affects control of cash and assets. Transfers, returns to ordinary management and enforcement should be monitored for consistency across relationship managers.

The second layer is third-party appointment. Consultant panels should disclose ownership, beneficial interests, prior relationships, fees, outcomes and complaints. Customers should receive choices where feasible. The bank should prohibit personal benefits and test employee and consultant connections using payment data, declarations and independent intelligence. Any override should be approved outside the business line.

The third layer is credit and valuation control. Additional facilities should state purpose, milestones, repayment source and downside case. Systems must enforce delegated limits and prevent one manager from splitting or sequencing approvals to avoid authority thresholds. Valuations should be independent, dated and stress-tested. Adviser fees and asset sales should be reconciled to approved plans.

The fourth layer is customer voice. Complaints alleging coercion, conflict, forged documents, diversion of funds or retaliation require a protected path to legal and financial-crime teams. Similar allegations across businesses should aggregate. Customers should be able to correct factual records before irreversible enforcement, subject to urgent asset-protection needs.

The fifth layer is fraud escalation. Investigators should preserve emails, payment trails, authority logs and customer evidence. A cross-functional committee should decide regulator and police reporting based on suspicion thresholds, not criminal proof. The board should see what is known, what is disputed, affected exposure, customer-protection actions and the reason for any delay.

The sixth layer is remedy independence. Population identification, methodology, experts, determinations and appeals should be controlled outside the function defending the bank. Customers should see material evidence and receive reasons. Quality assurance should sample exclusions and low awards, not only completed high-value cases. Methodology changes should trigger retrospective checks where they could affect earlier outcomes.

The seventh layer is institutional learning. Data from credit, fraud, human resources, complaints, litigation and redress should join one case graph. The system should identify recurring consultants, staff, assets, addresses and payment recipients. Access and privacy controls remain essential, but fragmentation cannot excuse failure to recognise a pattern.

The eighth layer is board proof. Directors should receive trend data on impaired customers, overrides, consultant concentration, complaints, investigations, reporting decisions and remediation ageing. Minutes should show challenge. Remuneration and consequence management should reflect control failures even where individual criminal culpability is absent.

Automation can support these controls but cannot decide fairness alone. Entity matching may reveal relationships, and workflow rules can enforce limits, yet source data can be incomplete or disputed. Models should expose confidence, lineage and exceptions. A human reviewer independent of the business must retain authority to stop lending, replace a consultant, report suspicion or reopen a remedy.

Proving that remediation is independent and complete

Completion requires more than saying that every person received an initial decision. The process should publish a population waterfall: potentially affected businesses, people assessed, inclusions, exclusions, fixed-sum offers, full reviews, challenges, final decisions, payments and unresolved cases. Privacy can be protected while totals and methodology remain transparent.

File testing should begin with the customer's account and the bank's contemporaneous records. Reviewers should trace transfer into impaired assets, consultant appointment, facilities, payments, asset disposals, complaints and enforcement. They should identify which facts derive from conviction, regulator finding, bank record or customer evidence. The lower remedial threshold should be stated, not hidden behind court language.

Independence is observable through authority. Can the panel compel records from the bank? Can it appoint its own experts? Can it disagree with bank legal analysis? Can a customer challenge an expert assumption? Can the appeal body change population, causation and quantum decisions? Can aggregate findings reach the board and regulator without management editing? Governance documents should answer those questions.

The 2017 FCA investigation statement shows how procedural status changes over time: the regulator resumed an investigation that had been paused at police request during the criminal case. Similar precision should govern remediation reporting. “Opened,” “paused,” “initial decision,” “challenged,” “settled” and “complete” are distinct statuses.

Operating proof should also extend beyond historic cases. A bank should test current impaired-assets portfolios for consultant concentration, authority overrides, unusual payments, complaint clusters and delayed fraud reporting. Independent assurance should sample decisions under commercial pressure and verify that a control owner can refuse an appointment or stop enforcement. Training and policy updates are inputs; timely detection and corrective action are outcomes.

Business continuity, consequence management and public trust

The harm from misconduct in an impaired-assets function is not limited to a bank balance or one business owner. A distressed company may employ staff, buy from suppliers, serve customers and support a local economy. Decisions about facilities, advisers and asset sales can determine whether wages are paid, contracts continue and viable operations survive. This does not mean every failed business would have recovered without the fraud. It means remediation must examine the counterfactual with enough operational detail to avoid treating insolvency as inevitable merely because the customer was already vulnerable.

Continuity evidence should include orders, margins, working-capital cycles, alternative finance, customer concentration, management capability and the timing of bank actions. A credible counterfactual may conclude that a company would still have failed, would have survived in a smaller form or would have achieved a sale at a different value. The reviewer should explain the path and probability rather than choose between total success and total failure. Consequential-loss analysis should test mitigation realistically: a director deprived of records, credit and cash cannot be assumed to have obtained replacement finance on ordinary terms.

Personal consequences require a separate method. Directors may have given guarantees, refinanced homes, incurred tax or legal costs and experienced severe distress. Some effects are financial and capable of documentary calculation; others call for consistent non-financial awards. The process should avoid using distress compensation as a substitute for direct or consequential loss. It should also avoid demanding intrusive evidence beyond what is necessary to assess a claim, especially after a prolonged institutional delay.

Consequence management inside the bank should follow role and evidence. Criminal conviction produces one set of consequences. A regulatory breach, failure to escalate, inadequate supervision or poor remedy design may justify other action even without dishonesty. The board should document which senior roles owned the relevant controls, what information they received, whether reasonable challenge occurred and how remuneration or continued responsibility was assessed.

Collective organisational failure cannot become a reason for individual accountability to disappear, but hindsight cannot replace the standards and information available at the time.

Professional advisers also need defined accountability. Lawyers, accountants, insolvency practitioners, valuers and consultants may perform different tasks under different duties. Appointment by a bank does not make every adviser part of the bank's decisions, and appearance in a customer file does not imply misconduct. Reviews should identify the instruction, evidence supplied, conflicts checked, work performed and reliance placed on the advice before drawing conclusions. Referrals to professional regulators should be reported as referrals until a final outcome exists.

Public trust depends on explaining these distinctions without losing the human reality. Overly broad statements can be unfair to people never found culpable and can weaken reliable findings. Overly narrow statements can hide systemic responsibility behind entity names and legal compartments. The solution is an accountability map that connects actors while preserving each legal lane: criminal convictions for named individuals, regulatory findings against the bank, independent review findings about remedy, corporate reporting about provisions and current procedure, and customer-level decisions under the redress scheme.

Boards should publish enough aggregate information to let outsiders test progress. Useful disclosures include process population, case stages, challenge outcomes, methodology changes, aggregate categories of award, operating costs separated from compensation and the expected next milestone. Any inability to publish because of privacy, privilege or continuing proceedings should be explained rather than used as a general shield. When a review has no confirmed completion date, reporting should say so plainly and provide the last independently verifiable status.

Finally, institutional memory must survive personnel and system changes. The Reading fraud, criminal investigation, FCA actions and successive reviews stretched across many years and corporate transitions. Records should preserve source documents, decisions, dissent, customer accounts and the basis for payments in a searchable but controlled archive. Future investigators and boards should not have to reconstruct the event from fragmented mailboxes or public controversy.

A durable archive is not only for litigation; it allows the bank to compare current control signals with a known failure pattern and act before harm becomes a generational grievance.

Conclusion

HBOS Reading became a banking-governance accountability test because criminal conduct exploited a setting in which distressed businesses depended heavily on bank decisions, while institutional warnings, reporting and remedy unfolded over many years. The six convictions established individual criminal responsibility within their defined cases. They did not criminally convict Bank of Scotland, HBOS or Lloyds. The FCA's GBP45.5 million penalty established a serious disclosure failure under regulatory duties, not a bank conviction for participating in the fraud.

The remedy history is equally specific. The voluntary Griggs Review produced settlements but was later found by Cranston to have serious methodological and process flaws. That did not make every award wrong; it required a more independent re-review. The Foskett Panel had delivered an initial decision to the identified population by the 2025 reporting date, while some challenges and outstanding cases remained. The separate Dobbs Review concerned post-acquisition knowledge, investigation and reporting and was still unpublished on 19 July 2026. Its conclusions cannot be anticipated.

Durable repair depends on evidence at every gate: why a business entered impaired assets, why a consultant was chosen, who approved lending, where money went, how conflicts were checked, when suspicion was escalated, what the regulator and police were told, how victims were identified, how losses were calculated and whether an appeal was genuinely independent. Provisions, offers, awards, confiscation and cash recovery must remain distinct measures.

A bank proves accountability not by owning the remedy in name, but by giving independent decision-makers the information and authority to challenge the bank, correct outcomes and demonstrate that the same concentration of power cannot again operate without scrutiny.