Internal Investigation: How to conduct an investigation without damaging your business

Internal Investigation: How to Conduct an Investigation Without Damaging Your Business Practical Guide for Owners and Top Management
Mainstream
Internal investigation is not about finding the guilty. It is a strategic tool for protecting business.
The question is not who broke the rules. The main question is how to stop the problem, minimize reputational damage, prepare for possible claims of regulators and not paralyze the company’s operations.
Any effective internal investigation begins with three checks:
How to ensure legal protection (privilege) of the collected materials.What regulatory, criminal and civil risks have already arisen and how to stop them.
If these issues are not resolved before the first interview, the company risks turning a local incident into a full-blown corporate crisis.
When an internal investigation is required
An internal investigation is necessary if:
- Reports of fraud, corruption, theft or conflict of interest
- The employee reported violations on the hotline (whistleblowing)
- A suspicious transaction or financial anomaly has been detected
- there are signs of bribery, commercial bribery or violation of the sanctions regime
- a due diligence check is carried out or an M&A transaction is being prepared
- the regulator has sent a request, order or subpoena
- There was a leak of confidential data
- facts of violation of antimonopoly, labor or migration legislation were revealed
- There are suspicions about top management or beneficiaries
- You need to make a decision on criminal protection, self-reporting or interaction with law enforcement agencies.
The mistake most companies make
Many managers respond to the alarm as follows:
Fire the guilty party immediately and forget it.
It's a dangerous approach. He's not answering questions: whether a crime has been committed, whether there is a systemic problem, how the regulator will react, whether there is evidence in the mail, whether the interests of the company are protected in a possible criminal case, whether the dismissal will provoke a counterclaim and destruction of evidence.
The right first question is:
How can an investigation be conducted to obtain objective facts, maintain control over the situation, protect the evidence base and not cause additional harm to business?
Sometimes the best outcome is not a loud exposure, but a quick fix of the violation while strengthening the compliance system. Sometimes, self-disclosure to the regulator in exchange for mitigation of liability. Sometimes it is a preparation for an inevitable public scandal with a clear legal and PR position.
Internal investigation requires not an emotional response, but a cold calculation of risks.
Step 1. Determine the objectives and boundaries of the investigation (Scoping)
The first thing to do is to clearly state what is being investigated.
Key questions:
- What is the alleged violation
- period
- which persons, units or legal entities are involved
- which jurisdictions are affected (especially critical for sanctions risks)
- who is the customer of the investigation – the board of directors, the audit committee, the sole owner
- Whether the investigation will be conducted under the auspices of external lawyers to maintain the privilege
Blurred boundaries of investigation ("look all") lead to uncontrolled costs, staff demotivation, leaks and the risk of going beyond the employer's legitimate interest.
Step 2. Provide legal privilege and confidentiality
The key element of protection is to maintain the status of confidential communication between the lawyer and the client (legal professional privilege).
In Russian law, this institution has limited effect, but with the right structure of the investigation, it can significantly complicate the seizure of materials by law enforcement agencies and exclude their use against a company in civil and corporate disputes.
This requires:
- appoint an external lawyer or law firm to lead the investigation
- All requests for documents by employees to formulate on behalf of the lawyer
- Working materials, analytical notes and interview minutes to prepare as confidential documents intended for obtaining legal advice
- clearly separate facts from legal conclusions
- Do not confuse the internal audit function with the legal defense function
In the absence of privilege, an internal report may be seized and read by an investigator, used by an opponent in court or a partner in a corporate conflict.
Step 3. Form an investigation team
The composition of the team depends on the nature of the incident, but the minimum configuration usually includes:
- External legal advisor – process manager, provides privilege and strategy
- Forensic specialist (financial audit, transaction analysis)
- IT-forensics (safety of email, messengers, recovery of deleted data)
- if necessary, a specialist in the protection of personal data and labor law
Internal employees (compliance, security, HR) may participate, but strictly under the guidance of external lawyers, so as not to destroy the privilege.
Step 4. Collect and secure evidence
Before the interview, immediate measures should be taken to preserve:
- e-mail (server copies, archive boxes)
- work files and folders
- correspondence in corporate messengers (Teams, Slack, WhatsApp)
- access logs to information systems
- financial statements, accounts, contracts
- surveillance footage
- visit-register
The most important principle is the immutability of data (forensic imaging) and the chain of custody (chain of custody). The slightest suspicion of altering or destroying evidence would undermine the trust of the regulator and the court, and could lead to independent liability for obstruction of justice.
Step 5. Conduct interviews with staff
Interrogation of employees is the most sensitive element. Mistakes here breed labor disputes, accusations of pressure and loss of valuable information.
Basic rules for conducting interviews:
- Interviews are conducted by lawyers, not security services.
- The lawyer is representing the company and not the employee (Upjohn warning / corporate Miranda)
- The employee is explained the obligation to maintain the confidentiality of the fact of the interview
- The protocol is prepared by a lawyer and protected by privilege.
- Physical and psychological pressure is excluded
- if there are signs of a criminal case against the employee, it is recommended to offer him the right to his own lawyer (especially in jurisdictions with developed protection of rights)
The purpose of the interview is to get facts, not to get recognition at any cost.
Step 6. Analyze the data received
Facts must be separated from assumptions. Each conclusion should be based on documents and evidence.
At this stage, it is important to answer the questions:
- whether the violation is confirmed
- Whether it is systemic or singular
- Whether there is a criminal offence or an administrative offence
- Are there any signs of damage to the company?
- What contractual or sanction risks are relevant
- who made the decisions and whether the company had adequate control procedures
The analysis concludes with a structured memorandum protected by privilege that will form the basis of management decisions.
Step 7. Assess regulatory and other risks
In parallel with the factual analysis, it is necessary to map all the potential consequences:
- obligation to notify the regulator (Bank of Russia, Rosfinmonitoring, law enforcement agencies, OFAC, the US Department of Justice – depending on the jurisdiction)
- Risks of secondary sanctions
- Risks to licenses and permits
- personal responsibility of members of management bodies
- risk of default on credit agreements (often contain assurances of compliance)
- reputational damage and partner/client reaction
Self-disclosure can be a mitigating factor, but only if it is done in a timely, complete and on terms that are beneficial to the company. A rash message can trigger a chain reaction of investigations.
Step 8. Prepare a report and recommendations for decision makers
The final report shall contain:
- description of activities undertaken
- established facts (with reference to evidence)
- Assessment of violated norms and possible liability
- Systemic Cause Analysis (Why Control Failed)
- recommendations on disciplinary measures (dismissal, recovery, suspension)
- Remediation plan and modernization of compliance system
- Legally justified position on interaction with regulators
The format of the report depends on the audience: For the board of directors, one version is one, for the regulator – another (strictly factual, without privileged estimates). You can't mix them.
Step 9. Implement a Remediation Plan (Remediation)
Regulators around the world are assessing not only the fact of a breach, but also what the company did after it was discovered.
An effective correction programme shall include:
- cessation of illegal practices
- Disciplinary measures against the guilty
- reparation
- strengthening internal policies and procedures
- staff training
- personnel changes, if necessary
- Enhancing compliance and “tone from above”
Demonstrating real rather than paper changes is often the main argument in negotiating a reduced fine or a waiver of criminal prosecution of a company.
Step 10. Managing communications
The information vacuum during the investigation is filled with rumors. It is necessary to think in advance:
- Who will be the official speaker (usually an outside lawyer or a specially trained representative of the company)
- What messages will employees receive (without details, but with confirmation that the situation is under control)
- How and when to notify banks, contractors, insurers, if required
- What will be the public position in the event of a leak in the media?
- How to interact with the regulator: actively or strictly within the scope of requests
The goal of a communication strategy is to maintain trust in the company and prevent the chaotic spread of information.
Internal investigation: by themselves or with the involvement of external lawyers
| Criteria | Internal Legal Department | External lawyers and forensic |
|---|---|---|
| Legal privilege | Weak or absent in Russia | Maximum achievable with the correct structure |
| Independence | Questioned (subject to management) | High (report to the appointing authority) |
| Confidentiality | High risk of leakage within the company | High control over information |
| Admissibility for the regulator | Often low | Higher (a sign of serious attitude) |
| Cost | It seems lower, but the cost of error is high. | Higher direct cost, lower overall risk |
| Special skills (IT-forenzik, sanctions) | Usually limited. | Access to specialist experts |
The choice depends on the severity of the incident, the jurisdictions affected and the potential scale of the damage. At the slightest risk of criminal or regulatory liability, it is reasonable to engage outside consultants with experience in protecting privileges and interacting with law enforcement.
How to Prepare for a Possible Investigation in Advance
The best investigation is one that can be done quickly and in a controlled manner, thanks to the infrastructure that has been built in advance.
It is recommended to have:
- Internal investigations policy (protocol approved by the Board of Directors)
- Regulations for interaction between IT, HR, security and lawyers in case of fixing an incident
- Corporate hotline with confidentiality guarantees
- Email and messenger policies that allow for monitoring within the law
- Data retention policy and the mechanism for emergency deletion blocking (legal hold)
- Framework agreements with external forensic specialists and law firms to avoid wasting time in a crisis
These measures allow the first day of the incident to turn on the mechanism, rather than improvise in panic.
Common mistakes in conducting an internal investigation
- Ignoring privilege. Materials created without the involvement of an outside lawyer can become evidence against the company.
- Rushing to get fired. You can lose the opportunity to get the full picture and provoke the destruction of evidence.
- Conducting interviews with security forces. It creates risks of accusations of abuse of power and pressure.
- Failure to ensure the safety of data. Deletion of correspondence after a signal of violation is an independent composition of the obstruction of justice.
- Ignoring the cross-border aspect. Different laws on personal data and blocking evidence (e.g. GDPR) may make it inadmissible to collect in one country.
- Untimely or incomplete disclosure to the regulator. Could turn a witness into a suspect.
- Mixing investigative and PR functions. Public statements without legal reconciliation can create irreversible consequences.
- Lack of a clear plan of correction. Punishing the perpetrators without eliminating the systemic cause ensures that the incident will happen again.
Checklist of the head before the investigation
Before you give the command to “start,” make sure you answer 15 questions:
- What is the specific purpose of the investigation and who is the customer?
- Which jurisdictions are potentially affected?
- Is there a duty to notify the public authority immediately?
- Is an external legal adviser appointed to protect the privilege?
- Is there a legal retention notice (Stop Deletion) order?
- Is there a list of people whose emails and files will be saved?
- Who will conduct the interview and according to what protocol?
- How to ensure confidentiality and minimize rumors in the team?
- Is there a conflict of interest among members of the investigation team?
- Are there any signs of criminal activity by the top management?
- Is the communication plan ready with key counterparties and banks?
- Are employees’ personal data protected in the process of collecting information?
- What is the budget and time frame for the first phase?
- Who decides on self-reporting and on the basis of what criteria?
- Is there a mechanism to protect the applicant from retaliation?
What a strong internal investigation strategy looks like
A strong strategy usually includes five levels:
- Legal shell. Protecting privilege, confidentiality and the chain of ownership of evidence from the first minute.
- Factual basis. Collection of complete, unchanging and reliable information (IT-forensic, financial analysis, testimony) without emotions and conjectures.
- Risk mapping. Legal qualification of actions and calculation of all types of liability – from administrative to sanction and criminal – in each affected jurisdiction.
- Protective circuit. Plan of engagement with regulators, law enforcement and contractors, including a decision on voluntary disclosure or passive defense.
- Corporate wellness. Disciplinary measures without disrupting critical functions and systemic changes that exclude relapse and demonstrate the integrity of the company.
Without the fifth level, the investigation is only a statement of the problem, not a tool for solving it.
FAQ
Should I inform the regulator of the results of the internal investigation?
Not always. The obligation arises if the law explicitly requires notice (e.g., suspicious transactions, personal data incidents or crimes in individual cases). In other situations, a voluntary disclosure decision is a tactical choice based on an assessment of risks and possible benefits.
Can an employee be fired after an investigation?
Yes, if sufficient evidence of the guilty actions has been obtained and the procedure established by the labour legislation has been strictly followed. It is important that the material collected can be presented in court without destroying the privilege of the main part of the investigation.
How to protect materials from seizure by law enforcement agencies?
There is no absolute protection, but a significant part of the documents created under the supervision of an external lawyer in the framework of legal assistance, has an increased protection status. Searches, seizure of servers and interviews of employees require an immediate response - the plan of action during the search must be ready in advance.
Who should decide to start an investigation?
Ideally, an independent body (a board of directors, an audit committee, but not the immediate head of the suspect). If the incident concerns the CEO, the decision must be made by the board of directors or the owners of the company.
Can I use personal phone records from employees?
The limits of control of personal devices are limited by the legislation on privacy of communications and personal data. BYOD (Bring Your Own Device) must be written in advance. Actions without legal basis may be considered illegal, and evidence inadmissible.
What if the violation is related to a foreign element and sanctions?
Lawyers specializing in the sanctions law of the relevant jurisdiction should be immediately involved. Parallel investigations in different countries, asset freezes and the risk of secondary sanctions require the strictest coordination. Any wrong action can make things worse before losing a business.
Could an internal investigation trigger a business shutdown?
Yeah, unless you control the scale. The seizure of all servers, the mass refusal of employees to communicate, leakage to the media are the real consequences of an unprofessional approach. Scoping and communication are key management decisions.
What is the difference between an internal audit and an internal investigation?
Internal auditing is aimed at verifying the effectiveness of processes and identifying deviations for management. Internal investigation is a legally oriented process of collecting facts about a specific possible violation, the main purpose of which is to protect the company and prepare for external claims.
Related services
- Corporate Investigations, Regulatory Investigations & Business Integrity
- White-Collar Crime, Regulatory Offences & Individual Defense
- Sanctions, Export Controls & International Compliance
- Compliance, Internal Controls & Risk Management
- Data Protection, Privacy & E-Discovery
- Corporate Governance & Directors’ Duties
Related material
- How to Build a Compliance System in an International Company
- The Company's actions during the search: guide
- Attorneys’ secrecy and confidentiality of internal investigation in Russia
- International sanctions and compliance checks of counterparties
- How to organize a hotline for whistleblowers without risks
- Anti-corruption compliance: from politics to practice
- What to do if the top management became involved in a criminal case
- IT-forensic and collection of electronic evidence in corporate disputes
- Self-reporting: When and how to report violations to the regulator
- Asset Protection in Cross-border Regulatory Investigation
Conclusion
Internal investigation is not a blame-finding operation, but a comprehensive strategy to protect businesses from legal, reputational and financial losses.
A strong position is based on precise target definition, immediate legal protection of materials, flawless evidence collection, a cold assessment of regulatory risks and a pre-conceived plan to correct the situation.
In a crisis situation, the winner is not the one who fires faster. The winner is the one who controls the process, protects privacy, and manages the consequences in a way that preserves reputation, assets, and business continuity.
Have a question about the topic of this article?
Write to us and we will respond within one business day.


