Between 1999 and 2015, more than seven hundred sub-postmasters in the United Kingdom were prosecuted for theft, fraud and false accounting. Most pleaded guilty. Some served prison sentences. Several lost their homes. At least four died before the matter was resolved. The convictions rested on evidence produced by Horizon, an IT system built by Fujitsu and rolled out across Post Office branches from 1999 onward. The Post Office maintained, in court after court, that Horizon was reliable and that its records were accurate. That claim was false, and the Post Office knew, earlier than it admitted, that it was false.

The Post Office Horizon scandal is not the largest software failure in financial terms, and it is not the most technically complex. What distinguishes it from every other entry in the catalogue of enterprise systems gone wrong is the criminal dimension. Software bugs became evidence. Evidence convicted people. The system was not merely a failed implementation — it was the instrument of a sustained injustice, and the question that runs under the whole history is how an institution came to treat its own audit trail as infallible when the people producing its numbers told them otherwise.

What Horizon was, and what it got wrong

Horizon was commissioned in the 1990s as a joint project to automate benefit payments and Post Office branch accounting. The Benefits Agency withdrew from the programme in 1999 after costs and scope had already expanded substantially; the Post Office proceeded alone. Fujitsu, as the prime contractor, delivered a system built on Windows-based terminals connected to a central accounting ledger. Each branch reconciled its accounts — cash, stamps, financial products — against the central record at regular intervals. When a discrepancy appeared between what the terminal recorded and what the branch held in its till, the shortfall was the sub-postmaster's problem.

A bound ledger open under one lamp, black surround

Before the software, the deadline. The close is older than every system that serves it.

Thraex picture desk

The architecture contained bugs. Some caused phantom transactions — credits or debits appearing without a corresponding physical event in the branch. Some caused double-counting. Some could be triggered remotely by Fujitsu engineers with access that sub-postmasters were never told existed. The crucial point is not that bugs are unusual in large enterprise software — they are not — but that the system was never formally tested for the reliability required of evidence in criminal proceedings, and the Post Office never disclosed to defence teams that it knew of defects. In English law, a prosecution is obliged to share information that undermines its own case. That obligation was repeatedly not met.

The sub-postmasters who reported discrepancies were told by the Post Office that no one else had experienced the same problem. This was untrue. Complaints were accumulating. An early mediation scheme, established under political pressure, settled some cases without acknowledgment of systemic fault. The pattern of denial held for years because the institutional incentive was clear: admitting that Horizon was unreliable meant admitting that every prosecution built on Horizon evidence was potentially unsafe, and the number of such cases was very large.

The record catches up

Freedom of Information Act requests, journalism — particularly from Computer Weekly, which began publishing detailed technical reporting in 2009 — and the persistent work of the Justice for Subpostmasters Alliance kept pressure on the institution. In 2019, a group litigation brought by more than five hundred sub-postmasters against the Post Office reached the High Court. Mr Justice Fraser's judgment ran to hundreds of pages. He found that Horizon had contained bugs, errors and defects, that the Post Office had misled the court in earlier proceedings, and that its conduct had been, in his phrasing, the "21st century equivalent of maintaining that the earth is flat."

Chronology

  1. 1999Horizon rolls out across Post Office branches; Benefits Agency withdraws from the original joint programme
  2. 2009Computer Weekly begins detailed public reporting on Horizon discrepancies
  3. 2019–2020High Court group litigation; Mr Justice Fraser's judgment finds systemic Horizon bugs and Post Office misconduct
  4. April 2021Court of Appeal quashes 39 convictions in a single judgment
  5. 2024Post Office (Horizon System) Offences Act quashes remaining convictions by statute
  6. 2021–presentPublic inquiry chaired by Sir Wyn Williams taking evidence

The Court of Appeal quashed thirty-nine convictions in April 2021 and has continued quashing further cases since. The Court of Appeal's April 2021 judgment established the principle that where the prosecution had relied on Horizon data and had failed to disclose known defects, the convictions could not stand. Parliament subsequently passed the Post Office (Horizon System) Offences Act 2024, which quashed remaining convictions by statute rather than requiring each affected person to pursue an individual appeal — an extraordinary legislative intervention, enacted because the ordinary appeals process was too slow given the number of cases and the age of many of the people waiting.

A public inquiry chaired by Sir Wyn Williams has been taking evidence since 2021. The inquiry's published evidence includes Fujitsu internal documents, Post Office legal correspondence, and witness accounts from sub-postmasters, legal advisers and senior executives. The evidence record has placed on the public record what the litigation had established: that people inside both Fujitsu and the Post Office were aware of Horizon's problems while convictions were still being sought and obtained.

What the record means for enterprise software

The Horizon case is extreme precisely because criminal prosecution is not the normal consequence of an enterprise system's accounting errors. But the structural conditions that produced it are not extreme at all: a vendor contractually motivated to defend its system's integrity, an institutional client that had staked its credibility on that system's reliability, a power imbalance between the institution and the individuals whose records the system generated, and an audit trail treated as authoritative because it was machine-produced.

A stack of unlabelled floppy disks, macro

Distribution in the 1980s: one program, one machine, one box.

Thraex picture desk

Those conditions exist wherever a large organisation runs a centralised system whose outputs are used to make consequential decisions about people who have no access to the underlying records. The particular severity of Horizon's consequences came from the additional element of criminal prosecution, but the template — system error attributed to human error, at scale, for years — is legible to anyone who has worked in enterprise systems long enough to see how a defect report travels, or fails to travel, up an institution's chain of concern.

Compensation has been paid to some; the full programme was still running as of 2025. Criminal referrals relating to the conduct of individuals within the Post Office and Fujitsu have been made to prosecutors. No convictions of individuals connected to the institutional conduct had been secured by the time this article was written. The prosecutions of seven hundred sub-postmasters took years to bring. The reckoning has taken longer.