Post Office threatened to sue Fujitsu over missing audit data
- Reference: 1705680727
- News link: https://www.theregister.co.uk/2024/01/19/post_office_threated_lawsuit_inquiry/
- Source link:
The details emerged today as the public inquiry into the scandal — which saw 736 managers of local Post Office branches wrongfully convicted of fraud when errors in the EPOS and accounting system was to blame — heard that the publicly owned organization had threatened to sue the Japanese supplier of the £2.3 billion Horizon system.
The proposed lawsuit, which was later settled, was about one of the six known cases of missing data from audits shared with the Post Office that could have been used in evidence to prosecute victims in cases which took place between 1999 and 2015.
[1]
Paula Vennells, Post Office CEO between 2012 and 2019, has previously defended the Horizon system, and said she relied on assurances from Fujitsu that it was "like Fort Knox."
[2]
[3]
The proposed lawsuit involved the broken audit trail data identified in May 2001.
Lead counsel to the inquiry, Jason Beer, pointed out that evidence submitted by Fujitsu — which inherited the Horizon system when it bought British computer company [4]ICL in 2001 — showed it identified the broken audit trail while undertaking an audit data extraction for an internal crime manager in the Post Office in relation to an audit record query (ARQ). Fujitsu told the Post Office of the missing data, most of which was later recovered from backup tapes, but the public body was concerned about breach of contract.
[5]
A submission to the inquiry from Fujitsu said: "Following further correspondence, [the Post Office] and Fujitsu agreed to settle any claims regarding the possible breaches by Fujitsu of its contractual obligations in return for a payment of £150,000."
In his evidence to the inquiry today, Paul Patterson, director of Fujitsu Services Ltd, said the company had been aware of known or suspected issues with the ARQ, but the records were nonetheless relied on by the Post Office in a civil law and criminal proceeding brought against the subpostmasters.
He admitted that despite a codified agreement stating that the audit trail should have a level of security such that it could not be altered or deleted, Fujitsu could make insertions and amendments into data, which could have had an impact on Post Office brand accounts.
[6]
Patterson said: "Changes or any adjustments were agreed with the Post Office before any action would or would not [be taken in relation to bugs and errors and defects]. So I don't think it was a secret intervention. I think it was discussing, 'This bug, this error causes this… make change'."
The Fujitsu boss began the hearing with an apology. "Fujitsu apologizes and is sorry for our part in this appalling miscarriage of justice. This inquiry is examining those events … which involve many parties, not least Fujitsu and the Post Office but other organizations and individuals. At conclusion of the inquiry and the guidance from this inquiry, [we will] engage with government on suitable contribution and redress to the subpostmasters and their families."
Patterson told MPs earlier this week that Fujitsu bore moral responsibility for contributing to the compensation of wrongly convicted subpostmasters.
[7]Fujitsu will not bid for UK.gov business until Post Office inquiry closes
[8]Fujitsu gets $1B market cap haircut after TV disaster drama airs
[9]Post Office boss unable to say when biz knew Horizon could be remotely altered
[10]How governments become addicted to suppliers like Fujitsu
At today's inquiry hearing, Patterson said bugs, errors and defects in the system had been known about by all parties since the introduction of Horizon in 1999.
He was asked to respond to the fact that Fujitsu employees provided witness statements to the Post Office so it could prosecute subpostmasters, but generally, the bugs, errors and defects were not mentioned in the witness statements.
He said this was "shameful and appalling."
"My understanding of how our laws work in this country [is] that all of the evidence should have been put in front of the subpostmaster that the Post Office was relying on to prosecute them," Patterson said.
The inquiry continues. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZaqqvWW47fMNOW@9pnSNRAAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaqqvWW47fMNOW@9pnSNRAAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaqqvWW47fMNOW@9pnSNRAAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2001/06/21/icl_brand_put/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaqqvWW47fMNOW@9pnSNRAAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaqqvWW47fMNOW@9pnSNRAAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/01/19/fujitsu_pauses_uk_public_sector_contracts/
[8] https://www.theregister.com/2024/01/18/fujitsu_gets_1_billion_market/
[9] https://www.theregister.com/2024/01/17/post_office_inquiry_latest/
[10] https://www.theregister.com/2024/01/11/fujitsu_public_procurement/
[11] https://whitepapers.theregister.com/
Re: It a wonder why this happens
Ed Davey has adopted the exact same defence.
“They TOLD me it was all tickety-boo, and I trusted them. It’s not like my job as Post Office Minister required me to hold them to account or scrutinize them or anything…”
Somewhat elementary?
" despite a codified agreement stating that the audit trail should have a level of security such that it could not be altered or deleted, Fujitsu could make insertions and amendments into data "
I always thought that audit trails were by definition supposed to be write once, then read-only. However I do remember a SaaS accounting system I was engaged to deliver the security for, where the developers allowed invoices to be altered and deleted after issue. So maybe there's some business principle I've missed?
Re: Somewhat elementary?
Usually it is a copy on write type system though, so the deleted invoice is still there and marked as deleted, along with the date/time and user id of the person who deleted it, and the amended details, if any added as a new invoice, with some sort of cross-reference between them.
Then, a regular supplier/customer account statement would exclude the deleted items, but an audit trail query would show them.
Blockchain
Would have made this impossible.
#Justsaying
"despite a codified agreement stating that the audit trail should have a level of security such that it could not be altered or deleted, Fujitsu could make insertions and amendments into data"
Re: Blockchain
Blockchain within one entity just means that the one entity could rewrite the chain from scratch. There isn't anybody else to check that they haven't.
It a wonder why this happens
"Paula Vennells, Post Office CEO between 2012 and 2019, has previously defended the Horizon system, and said she relied on assurances from Fujitsu that it was "like Fort Knox.""
*No you see they TOLD me it was safe*
So you followed that up with an independent check right? Right?
*No!? They assured me everything was fine...*