Summary

  • In October 2018 Patisserie Holdings announced significant and potentially fraudulent accounting irregularities, a materially affected cash position and previously unreported liabilities. Trading in its AIM shares was suspended, urgent financing kept the group operating temporarily, and the holding company later entered administration. The collapse closed stores, cost more than 900 jobs and exposed the difference between reported cash, accessible cash and the complete population of bank debt.
  • The Financial Reporting Council's final audit decision is the controlling professional-discipline record for Grant Thornton UK LLP and engagement partner David Newstead. It records accepted failures across the 2015, 2016 and 2017 audits in revenue, cash, journals and fixed-asset additions. It expressly does not find fraud and does not make findings against people who were not respondents. Those boundaries must remain separate from company announcements, insolvency estimates, civil allegations and the still-open criminal case.
  • The Serious Fraud Office has charged four individuals, all of whom pleaded not guilty. Its case page, updated in February 2026, says the trial is listed for January 2028. Charges and allegations are not verdicts. No article about the accounting collapse should convert the existence of a prosecution, the audit respondents' admissions or an administrator's reconstruction into criminal guilt.
  • Durable accountability is not demonstrated by a new checklist alone. It requires a bank-account register independently matched to banks, direct electronic confirmations under auditor control, tests of post-year-end clearance, gross rather than net analysis of reconciling items, journal populations protected from management filtering, evidence-sensitive audit-committee escalation and sampled proof that remedial monitoring changes real engagements.

On 10 October 2018, Patisserie Holdings plc told the market that its board had been notified of significant and potentially fraudulent accounting irregularities and a potential material misstatement of the accounts. The company's financial position required clarification, and trading stopped. The contemporaneous AIM suspension notice is a narrow but important record: securities were suspended at the company's request pending clarification of its financial position. It proves the market event and timing. It does not prove who created any false entry, what every bank balance was or whether a criminal offence occurred.

Two days later, the board said that its initial investigation indicated net debt of about £9.8 million and that historical statements about cash had been misstated. It said at least £20 million was needed immediately to continue trading in the same form. The company's proposed-placing announcement records that emergency account in the board's own words. It is a company statement made during a crisis, not an independently adjudicated reconstruction. The distinction matters because early estimates changed as administrators and liquidators gained records and because alleged conduct is now the subject of unresolved criminal proceedings.

The central accountability question is not simply how a business that sold cakes could collapse. It is how assertions about cash and debt could pass through monthly close, management reporting, board review, an audit committee, three statutory audits and market disclosure without contradictory bank and transaction evidence forcing a halt. Cash is often described as easy to audit because a bank can confirm a balance. Patisserie Holdings demonstrates why that description is dangerously incomplete.

An auditor needs the complete population of accounts, independently controlled confirmation, proper treatment of uncleared lodgements and cheques, and a coherent view of facilities, drawn debt and restrictions. Confirming only accounts supplied by management can verify numbers while missing the accounts that change the conclusion.

Four evidence tracks must not be collapsed into one verdict

The public record contains different institutions answering different questions. Patisserie Holdings made market statements about what its board had been told and what urgent funding it believed necessary. Administrators and liquidators recorded assets, liabilities, sales, claims and recoveries for insolvency purposes. The audit regulator examined whether named audit respondents complied with professional requirements. Prosecutors later alleged criminal conduct by four defendants. Parliament and government reviews used the collapse as evidence in a broader debate about audit quality and corporate reporting.

Each track has its own proof standard, entities and procedural status.

The FRC's November 2018 investigation announcement illustrates that separation. It opened one investigation under the Audit Enforcement Procedure into Grant Thornton's audits of the financial statements for 2015 through 2017 and another under the Accountancy Scheme into the preparation and approval of financial information by the former chief financial officer. Opening an investigation was not a disciplinary finding. The later published audit disposition concerns the auditor and engagement partner; it cannot be treated as a verdict against company officers or as the outcome of the criminal case.

The definitive audit record is the FRC Executive Counsel's Final Decision Notice. Its opening warning is unusually useful: the notice was prepared after an investigation and admissions by the respondents, makes no findings against other people or entities, and should not be used as evidence of findings against non-parties. It also says its adverse findings are not a finding of fraud and do not depend on fraud. The audit failures would warrant sanction even if misleading information had been supplied by management, because an auditor's task includes responding to the risk that information is inaccurate or incomplete.

That boundary protects accuracy in both directions. It prevents audit failings from being inflated into proof of an alleged conspiracy. It also prevents the unresolved criminal process from becoming an excuse to understate settled audit findings. Grant Thornton and David Newstead accepted failures in the audits; the regulator imposed professional sanctions. Four defendants in the criminal case have pleaded not guilty, and no trial verdict exists. Both statements can be true because they address different actors, conduct and standards.

Cash verification begins with completeness, not confirmation

The most basic cash-control design starts before a balance is confirmed. The group needs an authoritative register of every bank relationship: legal entity, bank, branch, account identifier, currency, purpose, authorized signatories, online users, facility, security, opening and closure date, ledger code and status. That register cannot be owned only by the same finance staff whose representations it is intended to test. It should be reconciled periodically to independent bank data, treasury portals, bank charges in the ledger, interest, merchant-acquirer settlements, direct debits, cheque stationery and Companies House charges.

The FRC notice records repeated inconsistencies between management information and bank information. It describes a dormant account that had been reactivated and used without the fact being communicated to the auditor. That is a completeness signal. Once one supposedly dormant account is active, the audit response should widen: refresh the population directly with financial institutions, inspect all entities and trading names, search the ledger for unexplained bank charges and transfers, examine confirmation replies for facilities and related accounts, and reconcile account-opening authorities to board or delegated approvals.

Treating the discrepancy as an isolated clerical correction would miss the governance question.

Bank confirmation is strongest when the auditor controls the request, destination, reply and follow-up. A confirmation routed through management or supported by documents of uncertain provenance does not create the same evidence. The auditor must authenticate the bank contact, avoid reply addresses supplied solely by the client, resolve non-responses through independent channels and compare every confirmed account or facility with the entity's register. Electronic confirmation platforms can reduce interception risk, but technology does not cure an incomplete population.

The control objective is both existence of recorded cash and completeness of debt and accounts.

Cash also has attributes beyond a nominal year-end number. It may be restricted, pledged, held for another party or subject to set-off. A facility can exist without being drawn, while an overdrawn account is an actual liability. Netting positive and negative balances across entities can conceal liquidity and legal-ownership differences. A reliable close therefore records the gross positions by legal entity and applies accounting netting only after the relevant criteria are documented. The board needs an operational view of immediately usable cash and committed headroom, not merely the accounting presentation.

Reconciling items are claims about time and existence

A bank reconciliation explains the difference between the ledger and bank statement at a defined time. It is not a parking area where an unsupported number can remain until the next period. Every outstanding lodgement claims that a specific receipt existed at year end and reached the bank later. Every outstanding cheque claims that an obligation had been validly issued but not yet presented. The evidence must connect amount, payer or payee, transaction date, ledger posting, bank clearance and commercial purpose.

The final decision records extremely large reconciling items: £3 million for 2015, £17.3 million for 2016 and £11.1 million for 2017. It notes, for example, a bank letter balance of £543,261 alongside £10.6 million of reconciling items for one account. Those figures did not merely call for a larger sample. They called for a different theory of the risk. Where the reconciliation adjustment dwarfs the bank-confirmed balance, the ledger cash is substantially a claim about items outside the independent record.

The auditor should test the entire material population, trace subsequent clearance and stand back from individual tick marks to assess the gross anomaly.

Cut-off testing must be bidirectional. Receipts recorded before year end should be traced to dated bank credits and underlying sales or debtor records. Bank credits after year end should be inspected for whether they were inappropriately pulled backward. Payments and cheques should be tested for delayed recognition, post-dating or exclusion from the payable population. Returned items require follow-up. Old reconciling items should not roll forward invisibly.

A dashboard that reports only the net unreconciled amount can hide large offsetting errors, so governance reporting should show gross outstanding receipts, gross unpresented payments, ageing and subsequent clearance.

This is where enterprise software can either strengthen or weaken accountability. Automated matching can clear thousands of ordinary transactions efficiently, but its rules, tolerances and manual overrides become audit evidence. Users should not be able to manufacture a match by changing dates or references without an immutable log. Unmatched items above risk thresholds should escalate. Reports must include items manually forced, items cleared after long delay and adjustments posted directly to control accounts. Automation should expose the residual exceptions, not make them disappear behind a high match percentage.

Revenue evidence had to be read as a pattern

The FRC's adverse findings extend beyond cash because reported cash was connected to claims about revenue. The notice describes large purported receipts around year end and a failure to investigate unusual concentration. One cited example was a single payment on 28 September 2016 representing 73 per cent of the group's annual voucher revenue from one third-party company and eleven times the average monthly receipts in earlier months. A junior team member raised concern about another concentration, but the issue was not shown to have reached the engagement partner.

An isolated invoice may look regular while the population is implausible. Revenue analytics should therefore ask how daily and monthly sales, cash receipts, voucher redemptions, merchant-acquirer settlements, VAT, store footfall and gross margin move together. A sharp year-end surge needs commercial explanation and independent evidence of the counterparty, contract, delivery and payment. The audit team should confirm unusual counterparties through contact details obtained independently and inspect whether payments reverse, move between group accounts or relate to another obligation.

The control is not satisfied by agreeing a spreadsheet total to the general ledger when both originate from the same manipulated population. For a multi-site food business, source evidence can include point-of-sale data, card-settlement reports, voucher-platform records, till cash, bankings, inventory consumption and tax returns. No single stream is perfect, but contradictions across independent streams are informative. If purported sales rise without corresponding settlement, VAT, customer activity or product movement, the model should trigger investigation rather than accept a management explanation because the final ledger balances.

Audit planning also needs a fraud-risk response that survives time pressure. Year-end transactions, manual revenue postings, related or unfamiliar counterparties and entries just below thresholds should not be excluded by a generic sample. Teams should preserve the full population, document selection logic and compare it with prior years. A repeated anomaly is more concerning, not less, merely because it appeared in an earlier signed-off audit. Prior acceptance is not independent evidence.

Journal testing must preserve the population and the chain of challenge

Journals are how management turns operational transactions into financial reporting, corrects errors and makes estimates. They can also bypass ordinary subledger controls. Effective testing starts with a complete extraction that reconciles to the general ledger and retains preparer, approver, timestamp, source, account, amount, narrative and subsequent modification. The audit team must understand whether system administrators can alter records, whether backdated postings are possible and whether extracts omit entities, journals or deleted entries.

The FRC notice says inappropriate criteria produced an excessively large set of journals to test, compromising depth; some entries were untested and inconsistencies were unexplained. Other test results did not match recorded expectations, and approval was not adequately confirmed. This is a warning against confusing volume with coverage. Selecting thousands of entries without a risk-ranked method may be less effective than testing a smaller but defensible set of privileged-user, year-end, unusual-account, round-sum, weekend, reversal and management-posted journals, combined with targeted testing of all material exceptions.

Approval evidence should be substantive. A name in an export is not necessarily proof that the person reviewed the business rationale and support. The reviewer should be independent of preparation, have appropriate authority, see the underlying evidence and record why the entry is proper. For entries that affect cash, revenue, debt or suspense accounts, the reviewer should connect the journal to bank and operational evidence rather than accept a circular finance document. Override logs and failed approvals belong in audit-committee reporting when they indicate systemic control weakness.

Escalation is equally important. A junior's concern has value only if the engagement has a reliable route to a decision-maker and a record of resolution. The audit file should show the question, evidence requested, response, independent corroboration, conclusion and effect on other procedures. Silence, an undocumented conversation or a management assurance does not close a red flag. If the concern changes fraud risk, the partner, quality reviewer and audit committee should see it, and the team should reconsider other evidence obtained from the same source.

Documents of dubious provenance required authentication

The regulator described documents with missing logos, typing errors, incorrect addresses and formats that did not match their stated purpose. It also described a bank letter about a £4 million overdraft facility being misread as showing an account was £4 million overdrawn. The examples point to two separate duties: authenticate the provenance of evidence and read its actual content accurately. A document can be genuine but misunderstood, or apparently clear but fabricated. Both risks require competent review.

Authentication begins outside the document. Auditors should obtain counterparty contact details independently, verify domains and phone numbers, inspect metadata where appropriate, compare templates with documents obtained directly and confirm material transactions at source. A PDF sent by management is not strengthened because it contains a bank-like header. If anomalies appear, the response should expand across other evidence received through the same channel. The team may need forensic or technology specialists, but specialist involvement does not transfer the engagement partner's responsibility for the conclusion.

Review quality matters because obvious anomalies can become normalized when work is divided among many staff. Senior reviewers need time to inspect the underlying evidence, not just completion status. Engagement metrics should distinguish unresolved exceptions from administrative sign-offs. A quality-control reviewer should be able to reconstruct why the team believed the bank population was complete, why reconciling items existed and why unusual revenue was valid. If the file cannot answer those questions without oral recollection, it is not a durable accountability record.

Board and audit-committee oversight required independent liquidity evidence

Directors are responsible for the financial statements and safeguarding assets; the external auditor provides reasonable assurance rather than operating the company's controls. That allocation does not reduce the auditor's obligations, but it prevents a governance vacuum in which each entity assumes the other verified cash. The board should receive direct evidence of bank balances, facilities, overdue obligations, covenant headroom and short-term cash forecasts, with reconciliation between treasury, finance and operational data.

An audit committee should ask population questions. How do we know all accounts and overdrafts are listed? Which banks confirmed directly? What changed since last year? How much of ledger cash consists of uncleared receipts? Which reconciling items are older than expected? What unusual year-end revenue was recorded, and what independent evidence supports it? Which manual journals affect cash and revenue? What did internal control testing fail? A committee cannot perform the audit, but it can demand that material contradictions are visible and resolved.

The Parliamentary correspondence about Patisserie Valerie also connected governance to supplier payment practices. Suppliers are early sensors of cash stress: extended terms, late payments, disputed invoices and requests to defer settlement can contradict a public story of abundant cash. Payment-practice reporting is not a substitute for audited accounts, yet a board and auditor should treat a divergence between reported liquidity and persistent supplier distress as evidence requiring explanation.

Emergency funding bought time, not assurance

The October 2018 placing and chairman's loan supplied urgent liquidity after the discrepancy became public. Emergency finance can protect jobs and preserve options, but it does not validate the preceding accounts. Before committing rescue funds, decision-makers need a conservative cash bridge, verified bank positions, near-term payroll and supplier obligations, tax liabilities, facility status and downside scenarios. They should identify which assumptions depend on records still under forensic review.

The subsequent failure shows why rescue governance needs stopping rules. A board should state what additional facts would invalidate the plan, who controls disbursement, how related-party funding is approved and when insolvency advice is refreshed. Daily cash reporting should reconcile to banks and distinguish forecast from actual. New money should not be described as restoring solvency unless a defensible balance-sheet and cash-flow assessment supports that conclusion.

Market disclosure must also separate known facts, estimates and allegations. The company's October announcements were necessarily produced under pressure. Precision requires identifying the basis and date of estimates and correcting them as information improves. Investors should not have to infer whether a number is bank-confirmed, management-reconstructed or an administrator's later estimate. The responsibility to update does not permit early statements to be rewritten retrospectively as though later findings were known at the time.

Administration converted a reporting failure into losses for people

The holding company's public Companies House filing history records the formal progression: administrator appointment, proposals and statements of affairs, later moves into liquidation and continuing progress reports. Registry filings are authoritative records of documents lodged and procedural events. Values within an administrator or liquidator report remain the office-holder's dated estimates and updates; they are not a judicial award or a guarantee of final creditor distributions.

The collapse affected more than shareholders. Stores closed, employees lost work, suppliers faced unpaid balances and franchise or trading relationships were disrupted. The Insolvency Service's employee guidance told dismissed workers how to claim eligible redundancy pay, wages, holiday pay and statutory notice pay, subject to legal limits. Statutory payments provide an important safety net, but they do not prove that every worker was made whole or that all pension, notice and consequential losses were recovered.

Insolvency estimates require careful entity boundaries. Patisserie Holdings was a group with holding and trading companies. Cash, debt, employees, leases, inventory and claims may sit in different legal entities. A group headline can therefore obscure who owns an asset and which creditors have claims against it. Administrators and liquidators must preserve intercompany records, trace transfers and distinguish business-sale value from recoveries available in each estate after costs and priority claims.

The public Companies House insolvency record should be read as a procedural index, not as one final balance sheet. Progress reports change as claims are admitted, litigation develops and assets are realized. A creditor outcome can be reported responsibly only with the relevant estate, reporting date, class, amount received and uncertainty. The same discipline applies to statements about a business sale: continuation of parts of a trading brand is not continuation of the insolvent listed company or preservation of every store and job.

Professional discipline fixed responsibility to named respondents

The FRC sanctions announcement summarizes the disposition. Grant Thornton's £4 million financial sanction was reduced for mitigation, cooperation, admissions and early disposal to £2.34 million. Non-financial sanctions included three years of reporting on remedial action and impact, a root-cause analysis, a review of audit-practice culture relating to challenge, and additional monitoring of bank and cash work. David Newstead's financial sanction was reduced to £87,750, and he received a three-year prohibition on carrying out statutory audits and signing statutory audit reports, alongside declarations and severe reprimands.

The sanction amounts should not be compared directly with shareholder, creditor or employee losses as though they were compensation. Professional sanctions punish and deter breaches within the audit regime; insolvency distributions and civil litigation address other rights. Discounts reflect the enforcement procedure and cooperation, not a regulator's estimate that the underlying failings were less serious. Similarly, the declaration that audit reports did not satisfy relevant requirements does not cancel the separate need to prove loss and causation in a civil claim.

The FRC's public enforcement-case index provides the procedural context for imposed sanctions and commenced matters. It helps users distinguish an investigation from an outcome and an audit case from a non-audit accountancy case. That distinction is essential where a single corporate collapse generates several proceedings. A responsible accountability record should name the procedure, respondent, period, disposition and appeal or settlement status rather than use the generic phrase "the regulator found".

The audit findings also demonstrate why audit is not a guarantee against failure or fraud, but neither is it an exercise satisfied by collecting management documents. The FRC's plain-language description of an audit explains the reasonable-assurance opinion and the division between management decisions and auditor judgment. Reasonable assurance tolerates unavoidable detection risk; it does not excuse failure to authenticate evidence, pursue contradictions or apply professional scepticism to unusually large year-end transactions.

The criminal case remains open and allegations remain allegations

The SFO case page for Patisserie Holdings is the controlling current-status source. It says the investigation began in October 2018, four individuals were charged in September 2023, all four pleaded not guilty on all charges in April 2024, and the trial has been relisted for 4 January 2028. As of the page's February 2026 update, the case is open. Those facts prohibit any claim that the defendants have been convicted, that the alleged conspiracy has been proved or that a trial has resolved how the accounts were manipulated.

Charges allege conduct; they do not establish it. The presumption of innocence applies to every defendant. The company announcements used terms such as potentially fraudulent, while the FRC notice referred to an alleged fraud and expressly disclaimed a fraud finding. Insolvency office-holders may plead allegations in civil proceedings under different standards and for different remedies. An article may explain those records, but it must preserve attribution and procedural tense.

This boundary is not a technical footnote. Once an audit regulator has published detailed accepted failures, it is tempting to narrate a completed criminal story around them. Yet the audit respondents are not the criminal defendants as a group, and professional breaches do not prove the elements of conspiracy or false representation. Conversely, acquittal or discontinuance in a criminal case would not erase the FRC's separate audit disposition. Accountability depends on keeping each institution within its jurisdiction.

Civil claims and recoveries need their own evidential ledger

Liquidators can investigate transactions and pursue claims intended to increase recoveries for estates. A civil pleading records allegations advanced by a claimant, not findings. An interlocutory ruling may determine disclosure or procedure without deciding negligence, causation or damages. A settlement can produce recovery without admission or judgment, depending on its terms. Reporting must therefore identify what kind of document supports any recovery figure.

The filed insolvency record is the durable public location for dated office-holder updates, but it should not be compressed into a single timeless shortfall. Claims can be contingent, disputed or offset; estimated outcomes can change; costs and priorities affect distribution. A gross settlement or asset realization is not automatically the amount paid to unsecured creditors. The proper proof is a bridge from opening estimate through realizations, costs, priority distributions and the remaining balance by estate.

Investors also had different legal positions. A shareholder's market loss is not identical to a company's loss caused by an allegedly negligent audit, and neither is identical to a creditor's unpaid invoice. Civil causation may depend on who relied on which statement, when and for what transaction. The existence of professional sanctions can be relevant background but does not mechanically determine every private claim. A recovery should be described only when supported by a court order, executed settlement statement or office-holder report with the relevant qualifications.

Patisserie Valerie became evidence in the audit-reform debate

The House of Commons Future of Audit report placed Patisserie Valerie alongside other corporate failures when examining audit quality, competition, scope and regulation. It cited the administration, store closures and job losses as part of the public cost of weak confidence in audited reporting. Parliamentary findings and recommendations are policy evidence, not retroactive adjudication of the company's accounts or named individuals' criminal responsibility.

The Competition and Markets Authority's statutory audit services market-study report likewise noted the public interest in the audit and the then-ongoing FRC investigations. Its focus was market structure, incentives, choice, resilience and regulation. Patisserie Valerie illustrated the urgency of the problem; it did not mean that competition remedies alone would have detected the specific bank and journal anomalies.

Government's later Restoring trust in audit and corporate governance consultation addressed a wider package: public-interest-entity scope, directors' fraud reporting, auditor reporting on fraud-related work, stronger regulation and assurance. It recorded the view that AIM companies such as Patisserie Valerie raised questions about the boundary of heightened public-interest oversight. Policy proposals and later implementation must be distinguished; publication of a consultation does not prove that every proposed duty became law or that an audited entity implemented it.

The reform lesson is therefore layered. Better regulator powers may improve enforcement. Wider public-interest scope may increase inspection and reporting. Stronger competition or operational separation may affect incentives. Clearer director and auditor fraud duties may narrow the expectations gap. But none replaces the engagement-level act of obtaining a complete bank population, authenticating confirmations, testing reconciling items and escalating contradictory evidence. System reform and file-level competence are complements.

What durable cash and liability verification looks like

A repaired control environment begins with ownership. Treasury owns the bank register and daily cash view; finance owns ledger reconciliation and accounting treatment; legal or company secretarial records authorities and charges; operations provide independent sales and settlement data; internal audit tests design and operation; the audit committee challenges exceptions; and the external auditor independently tests the financial statements. Named owners do not create silos: each handoff must have a reconciliation and escalation route.

Monthly certification should be evidence-based. Every entity confirms its account population, changes and dormant accounts. Treasury matches the register to direct bank data. Finance reconciles each account and reports gross aged exceptions. Debt facilities, drawn balances, covenants and security are reconciled to agreements and confirmations. Merchant acquirer and voucher settlement accounts are included. Suspense, cash-in-transit and clearing accounts receive the same scrutiny as ordinary bank accounts because their labels can hide unsupported assets.

At year end, the auditor should obtain confirmations through controlled channels and perform alternative procedures only when they produce equivalent relevant evidence. The team reconciles all replies to the register and ledger, investigates additional accounts disclosed by banks, and tests restrictions and facilities. Reconciling items are traced to subsequent statements; large or unusual items are examined in full. Search procedures for unrecorded liabilities inspect post-year-end payments, supplier statements, bank movements, legal correspondence and tax accounts.

Revenue testing should connect the financial ledger to operational truth. The auditor develops expectations by store, product channel and period, then investigates outliers. Unusual voucher or wholesale transactions receive counterparty confirmation and proof of performance. Cut-off tests cover both sides of year end. Journal testing uses a complete, reconciled data set and targets management override, privileged users, unusual combinations and entries inconsistent with ordinary trading. Exceptions affect risk assessment across the engagement rather than remaining inside one workpaper.

The audit committee should receive a concise contradiction report. It identifies significant evidence conflicts, management explanations, independent corroboration, unresolved items and their possible financial-statement effect. The committee records whether it agrees with closure and why. Private sessions with the auditor and internal audit create a route around management filtering. Whistleblowing information, supplier complaints and unusual bank correspondence are integrated into the risk view with appropriate confidentiality controls.

Metrics must test outcomes, not completion

The FRC's remedial sanctions required reporting and additional monitoring, but a durable assurance model should ask what the monitoring found and whether behaviour changed. Completion measures—staff trained, templates issued, confirmations sent—are useful leading indicators. Outcome measures include the rate of undisclosed accounts found, unresolved confirmation differences, aged reconciling items, post-year-end reversals, high-risk journals without support, review findings repeated, audit files requiring substantial remediation and cases where challenge changed the opinion or disclosure.

Sampling matters. A firm can report that a policy exists while weak engagements avoid it. Independent reviewers should select engagements based on risk, not only volunteer files, and inspect the bank-population evidence from start to finish. They should test whether partner involvement occurred before conclusions hardened, whether quality reviewers saw the underlying exceptions and whether audit committees received candid communication. Findings should be tracked to root causes such as workload, incentives, skills, supervision or tool limitations.

Boards need similar testing. Internal audit can select bank accounts and trace their full lifecycle from authorization to register, ledger, reconciliation and closure. It can independently query banks for a sample of entities, inspect administrator privileges and recreate exception reports. It should challenge whether high automated-match rates reflect tight rules or permissive tolerances. Remediation closes only when repeat testing demonstrates operation over time, not when management uploads a revised procedure.

Public reporting must be proportionate but specific enough to create accountability. A statement that controls were strengthened is weaker than disclosure of what was changed, who tested it, what exceptions remained and what period was covered. Commercial confidentiality may limit detail, yet the company and auditor should retain an evidence package capable of regulatory inspection. The aim is not to promise that misstatement is impossible; it is to show that contradictory evidence reliably causes expanded work and governance action.

The accountability standard

Patisserie Holdings failed as an accountability system before it failed as a listed company. Reported cash was meaningful only if every relevant bank relationship and liability was in the population. A reconciliation was meaningful only if outstanding items represented real, correctly timed transactions. Revenue was meaningful only if operational and independent payment evidence supported it. Journal approval was meaningful only if reviewers understood the entry and its source. An audit opinion was meaningful only if anomalies changed the procedures and reached people with authority to act.

Responsibility remains actor-specific. Directors owned the accounts, assets, controls and market statements. The audit committee was responsible for governance challenge within its mandate. Management operated treasury, reporting and payment processes. The statutory auditor was responsible for sufficient appropriate evidence, scepticism, supervision and a defensible opinion. Administrators and liquidators managed estates and recoveries after appointment. The FRC enforced professional requirements. Prosecutors and courts control the criminal process. Parliament and government set policy.

Their duties intersect, but their findings are not interchangeable.

The employment tribunal's Patisserie Valerie case-management order is a small reminder of those real-world interfaces: employment claims arising from closures required coordinated procedure. It is not a finding on the accounting allegations, but it shows how corporate reporting failure travels into institutions far beyond the audit file. Workers, suppliers and investors experience delay and loss while technical and legal tracks proceed at different speeds.

Durable repair can be stated simply. Build the bank population from evidence independent of the ledger. Confirm both assets and facilities under auditor control. Treat reconciling items as assertions requiring subsequent proof. Analyze unusual revenue across the full population. Preserve journal completeness and privileged-user history. Give junior concerns a documented route to partner and committee decisions. Separate professional findings, criminal allegations, insolvency estimates and civil outcomes. Then test the controls repeatedly in real engagements.

Patisserie Valerie became an accounting accountability test because apparently ordinary evidence—bank letters, reconciliations, voucher receipts and journals—did not receive the challenge its contradictions demanded. The lesson is not that every audit should become a criminal investigation. It is that reasonable assurance depends on disciplined doubt, authenticated evidence and escalation. Cash verification is complete only when an institution can prove both sides of the proposition: the cash exists and is usable, and every account, overdraft and timing difference that could change that conclusion has been found.