Europe · Investigations and protection of business

How to Turn Internal Investigations into Corporate Governance Tools

Erich Rath10 min read

How to Turn Internal Investigations into a Tool for Better Corporate Governance A Practical Guide for Companies Operating in the European Union

Mainstream

Internal investigation is not a way to find and punish the guilty. This is a strategic opportunity to strengthen corporate governance.

The question is not who broke the rule. The main question is why the management system allowed this to happen and how to make sure that this does not happen again.

An effective internal investigation to improve governance begins with three checks:

  • What systemic flaws the incident revealed.
  • How to fix these shortcomings so that they do not lead to more serious consequences.
  • How to use the results of the investigation to strengthen compliance, control and corporate culture

If these three issues are not addressed, the company will spend resources on fact-finding, but will retain management vulnerabilities that sooner or later lead to losses, whether financial, reputational or regulatory.

When an internal investigation should be a tool for improving governance

Internal investigations aimed at governance are necessary if:

  • A report from whistleblower about serious violations has been received.
  • signs of fraud, corruption or theft within the company;
  • suspected of violating the EU sanctions regime or export controls;
  • the regulator has initiated a request or inspection;
  • systematic failures in compliance procedures were identified;
  • Pre-M&A due diligence is performed and risks are disclosed.
  • an incident involving the processing of personal data (GDPR) has occurred;
  • The effectiveness of the existing corporate governance system should be assessed;
  • The company integrates the business into the new EU jurisdiction and checks local compliance.
  • The board of directors or the supervisory board requires an independent assessment of the internal control system.

In all these cases, the investigation ceases to be simply an “incident analysis” and becomes a source of data for strategic decisions about the governance structure.

The mistake most companies make

Many companies start an internal investigation with the following questions:

Who is to blame and how to punish him?

That's the wrong first question.

The right question is:

What weaknesses in the management system did this incident reveal and how to fix it to prevent a recurrence?

An investigation focused solely on personal responsibility produces local disciplinary results, but does not protect businesses from systemic risks. On the contrary, a governance investigation turns even a negative situation into an investment in the sustainability of a company.

Step 1. Formulate the mandate of the investigation with a focus on management

Before you start collecting facts, you need to fix the objectives of the investigation. The mandate should explicitly include not only the establishment of circumstances but also the identification of systemic deficiencies and the preparation of recommendations for management.

Key elements of the mandate:

  • description of the incident;
  • the range of issues under investigation;
  • Indication of analysis of systemic causes;
  • the power to request documents and interview staff;
  • Require compliance with GDPR and national data protection regulations;
  • ensuring the privacy and protection of whistleblower in accordance with EU Directive 2019/1937;
  • Requires a report with recommendations to the Board of Directors.

The mandate, limited to factual research alone, almost always results in conclusions not being implemented at the governance level.

Step 2. Ensure independence and legal protection

In European practice, the quality of the investigation depends on its independence and compliance with legal guarantees.

It is necessary:

  • to engage external legal advisers to ensure independence;
  • assess the applicability of the attorney-client privilege in a particular EU jurisdiction;
  • ensure the protection of personal data in accordance with the GDPR at all stages;
  • document consent to data processing or the legal basis for it;
  • eliminate conflicts of interest among the participants of the investigation;
  • Ensure that there is no reprisal against whistleblower.

Failure to comply with these principles can not only undermine confidence in the results, but also create a company’s own regulatory risk.

Step 3. Collect and analyze data in the context of the system

Collecting evidence is not just a reconstruction of events. It is an analysis of how the elements of the management system worked (or did not work).

We need to prepare and study:

  • internal policies, codes, regulations;
  • procedures for coordination and control;
  • minutes of meetings of management bodies;
  • e-mail correspondence and corporate messengers;
  • ERP and accounting systems data;
  • materials of previous audits and audits;
  • compliance officer and internal audit reports;
  • Whistleblowing-messages and reactions to them.

Of particular value are not so much “compromising” documents as evidence of systematic circumvention of control, lack of response to warnings and gaps in the allocation of responsibility.

Step 4. Identify the root causes of the incident

The essence of a governance-based investigation is to go beyond personal error to root causes.

The root causes may lie in:

  • unclear distribution of powers;
  • conflict between KPI and compliance requirements;
  • absence of escalatory mechanisms;
  • insufficient qualification of members of management bodies;
  • Ignoring internal audit signals;
  • Culture of “result at any cost”
  • There are gaps in learning.

Until these causes are addressed, the company remains vulnerable even if the employee is fired.

Step 5. Risk assessment in the context of European regulation

The results of the investigation should be compared with the relevant EU requirements. This affects the priorities and urgency of the measures.

The analysis includes:

  • Violations of EU directives and regulations;
  • the risks under the Whistleblower Directive (Protection of Reporters)
  • risks under the GDPR;
  • risks under the legislation on due diligence in the supply chain (CSDDD, Lk SG and analogues);
  • sanctions risks;
  • responsibility of members of the governing bodies under national law;
  • Obligation to notify regulators (e.g. data breach notification).

The assessment allows not only to determine the scale of the problem, but also to build protection against potential public liability.

Step 6. Develop recommendations for the management system

The findings of the investigation should be translated into the language of governance.

Recommendations may include:

  • Change of the structure of compliance function;
  • redistribution of powers between management bodies;
  • introduction of additional levels of control;
  • updating the code of conduct;
  • Creating or reforming a whistleblowing channel
  • Change the reward system to eliminate conflicts of interest;
  • Regular reporting compliance to the Supervisory Board.

Recommendations should be specific, implementable and addressed directly to the body that is capable of implementing them.

Step 7. Implement changes in policies, procedures and IT systems

The implementation of the recommendations is a separate project, without which the investigation remains a paper.

The implementation process includes:

  • Developing new or changing existing policies;
  • updating of job descriptions;
  • ERP systems and approval flows;
  • introduction of automated controls;
  • Integration of compliance checks into business processes;
  • documenting the measures implemented to demonstrate to the regulator.

Systemic improvements should not be a declaration, but a real change in the management environment.

Step 8. Learning and changing culture

The most perfect procedure doesn’t work if people don’t understand it or accept it.

Training should include:

  • members of the Supervisory Board and the Board;
  • middle management;
  • Employees in high-risk areas;
  • Compliance specialists.

Training is based not only on the translation of the rules, but also on the analysis of a specific incident, demonstrating its consequences and explaining the relationship between the employee’s actions and the sustainability of the company.

Step 9. Communication with regulators and external stakeholders

In European jurisdictions, concealing systemic problems can have more serious consequences than the incident itself.

The communication plan should take into account:

  • mandatory notifications (data protection authority, financial regulators, etc.)
  • voluntary disclosure as a mitigating factor;
  • informing auditors;
  • Reputational risk management.

Correctly built communication demonstrates the maturity of the management system and can significantly reduce administrative sanctions.

Step 10. Embedding feedback into the management cycle

The investigation does not end with a report and implementation of measures. Governance effect is achieved when the company closes the cycle.

That means:

  • monitoring the implementation of recommendations after a certain time;
  • Including the findings of the investigation in the annual risk assessment;
  • adjustment of the compliance audit program;
  • Regular monitoring of whistleblowing messages as an indicator of system health.

Each investigation becomes a source of data for continuous improvement of corporate governance.

Investigation as a reaction against Investigation as a governance tool: comparison-table

CriteriaInvestigation as a reactionInvestigation as a management tool
PurposeEstablish the culpritUnderstand and eliminate the systemic cause
FocusPersonal responsibilitySystemic governance weaknesses
The resultDisciplinary recoveryEnhancing compliance environment
Top management involvementOften minimizedActive participation of the Board of Directors
Use of dataFor the report.Transforming policies and procedures
Cultural impactFear of punishmentEnhancing maturity and responsibility
Regulatory effectNeutral or negativeMitigation of responsibility, demonstration of good faith
Long-term protectionLow.Tall.

How to Prepare a Management System for Effective Investigations

The best investigation begins long before the incident.

Companies operating in the EU are encouraged to implement:

  • an effective whistleblowing channel that complies with the EU Directive;
  • clear procedures for conducting internal investigations;
  • predetermined procedure for attracting external consultants;
  • Regulations of interaction compliance, legal department and board of directors;
  • Training managers to recognize red flags;
  • Regular governance audits;
  • Integrating lessons from previous incidents into company policy.

A system that is ready for investigation can make the most of it.

Common mistakes in internal investigations

  1. To order an investigation without a clear governance mandate, the result remains at the level of facts without management conclusions.
  2. To conduct an investigation exclusively by the internal team - a conflict of interest and a decrease in objectivity are possible.
  3. Ignoring GDPR requirements – collecting and processing data without a legal basis creates additional risk.
  4. Failure to protect whistleblower – Violation of the EU Directive threatens sanctions and undermines trust in the system.
  5. Limit to disciplinary action: Systemic problems are not solved by firing one employee.
  6. Not involving the board of directors – recommendations do not get the necessary impetus to implement.
  7. Do not analyze previous incidents – recurring incidents indicate a chronic governance defect.
  8. Delay change – Over time, risk perceptions decrease and the company remains unprotected.
  9. Not to communicate with the regulator in the presence of such a duty - silence can be interpreted as bad faith.
  10. Not measuring the effectiveness of the measures implemented, it is impossible to know whether the quality of management has improved.

Checklist: 15 Questions to Turn Internal Investigation into a Corporate Governance Tool

  1. Is the investigation mandate clearly defined with an indication of systemic causes?
  2. Is the independence of the investigation guaranteed?
  3. Are the GDPR requirements complied with in the collection and processing of data?
  4. Is the privacy and protection of whistleblower guaranteed?
  5. What parts of the management system did they fail?
  6. Have there been any signals left unattended?
  7. What are the root causes of the incident that are not related to a specific employee?
  8. What European regulatory requirements are affected?
  9. Are the recommendations made directly to the board of directors or the supervisory board?
  10. Are there any people responsible for implementing each recommendation?
  11. Is there training for management and employees?
  12. Have policies and procedures been changed?
  13. Is the procedure for monitoring the implementation of measures defined?
  14. Is the need to inform the regulator assessed?
  15. Are the findings of the investigation embedded in the risk management cycle?

What a strong strategy for using internal investigation looks like for governance

A strong strategy usually includes five levels:

1. Fact-Finding with Governance Lens: Fact-finding with a focus on how management mechanisms functioned.

2. Root Cause Analysis is not about personal causes, but about systemic causes of an incident.

3. Governance Gap Assessment: Assessing the gap between the actual state of the governance system and the requirements of EU legislation and best practices.

4. Remediation & Integration Plan: Developing and implementing specific measures to strengthen control, policies and accountability structures.

5. Cultural & Board-Level Embedding – Consolidating change at the corporate culture level and regularly monitoring by senior management.

Without tier five, the first four can only provide temporary improvements, not sustained improvements, in corporate governance.

FAQ

Can an internal investigation be used to improve governance if the incident is minor? Even a small violation often indicates a systemic defect that could otherwise lead to serious consequences.

External consultants are necessary if the incident affects top management, there is a possible conflict of interest, there is a risk of regulatory intervention or attorney-client privilege protection is needed.

The processing of personal data during an investigation must be lawful, transparent, limited in purpose and accompanied by protective measures. Non-compliance in itself creates a risk of fine.

Ensure personal confidentiality, prohibit reprisals, create secure communication channels and inform the applicant in a timely manner about the progress of the communication.

Is the company obliged to report the results of the investigation to the regulator?Depends on the industry and the nature of the violation. In some cases (for example, personal data leakage), notification is mandatory. In others, voluntary disclosure may mitigate liability.

Can the investigation be turned into a tool for improving governance without the support of the board?Without the involvement of the highest management body, changes will be fragmented and unsustainable. Transforming governance requires will and resources at the highest level.

More importantly: For management purposes, the quality of the analysis of systemic causes and the implementation of recommendations is more important than speed. A hasty investigation almost always misses the governance dimension.

How to measure the effectiveness of implemented changes?Through key indicators: Reducing the number of incidents, increasing the activity of the whistleblowing channel, audit results, assessing compliance culture and regulatory risks.

Related services

  • Corporate Investigations, Regulatory Investigations & Business Integrity
  • Corporate Governance & Board Advisory
  • Compliance, Risk Management & Internal Controls
  • EU Whistleblower Protection & Data Privacy (GDPR)
  • Sanctions, Export Controls & International Compliance
  • Cross-Border Regulatory & Strategic Risk Advisory
  • White-Collar Crime & Directors’ Liability

Related material

  • Internal investigation in the EU: Whistleblower and GDPR protection – practical risks
  • How to build an effective compliance system in a European company
  • EU Directive on the Protection of Persons Reporting Violations: What's changed for business
  • Responsibility of members of governing bodies under German law
  • Corporate Governance and Due Diligence in the Supply Chain EU requirements
  • Attorney-client privilege in internal investigations: European characteristics
  • How to conduct a governance audit before an M&A transaction
  • Investigation as a mitigating factor: Interaction with regulators in the EU

Conclusion

Internal investigation is not only a tool for responding to violations. This is a unique opportunity for the company to objectively assess the real state of the corporate governance system and purposefully increase its maturity.

Companies that view investigations as a source of strategic information for the board of directors do not simply address the consequences of incidents – they create a sustainable management environment that can prevent risks, meet the growing requirements of European regulation and protect the value of business.

A strong governance strategy transforms internal investigation from an episodic response to a continuous cycle of corporate governance improvement.

Have a question about the topic of this article?

Write to us and we will respond within one business day.