Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Step-by-step procedure for investigating an internal fraud allegationAn internal fraud allegation can involve theft, falsified records, conflicts of interest, procurement manipulation, bribery, payroll abuse, expense fraud, or misuse of company data. The first response often determines whether the organization preserves reliable evidence and reaches a fair decision. A hurried accusation can damage reputations, while a delayed response may allow records to disappear or losses to grow. A sound investigation procedure combines fact-finding, legal awareness, confidentiality, and proportionate action. It should establish what was reported, protect relevant information, identify who must be involved, and test competing explanations without assuming guilt. The same principles apply whether the concern is raised through a whistleblowing channel, an audit review, a manager, or an external party. Companies operating across borders also need to consider local employment rules, privacy requirements, financial regulations, and anti-corruption obligations. Country risk profiles, compliance guidance, and practical training from the Business Anti-Corruption Portal can help investigation teams understand the wider control environment in which an allegation arose. Set the mandate and protect the processBegin by recording the allegation in neutral language. Note when it was received, how it was submitted, who received it, the people and business units named, the conduct alleged, the relevant period, and any immediate risk of loss or retaliation. Avoid converting an unverified report into a statement of fact. “The reporter alleges that purchase orders were approved for a related supplier” is more appropriate than “The manager committed procurement fraud.” Assign an investigation owner with suitable independence, authority, and expertise. Depending on the allegation, this could be internal audit, compliance, legal, human resources, security, or an external investigator. Anyone with a personal, reporting, or financial connection to the matter should be screened for conflicts of interest and removed from decision-making where necessary. Create a restricted case file and establish access controls from the outset. Preserve the original report, related correspondence, transaction records, and investigation decisions in a way that maintains an audit trail. Communications should be factual and limited to those who need the information. Confidentiality should be explained carefully: it protects the integrity of the process, but it cannot guarantee absolute secrecy where disclosure is required by law or necessary to investigate. Triage the allegation before investigatingTriage determines the urgency, scope, and resources required. First assess whether there is an immediate threat to money, systems, evidence, customers, employees, or regulators. A suspected payment diversion may require temporary changes to bank approval rights; a data theft allegation may require prompt technical preservation; and a retaliation concern may call for protective measures for the reporter. Do not use temporary safeguards as punishment. Suspending access, changing approval duties, placing an employee on leave, or restricting contact with a supplier may be appropriate when carefully documented, but such actions should be proportionate and reviewed regularly. The purpose is to prevent interference and further harm, not to signal that the allegation has already been proven. The initial assessment should also identify related risks. An apparently isolated invoice may reveal a broader scheme involving a vendor, intermediary, family member, or public official. Review whether the conduct could involve bribery, money laundering, books-and-records violations, sanctions exposure, procurement collusion, or a breach of contract. Guidance on mapping supply-chain risks is especially relevant when the allegation concerns third parties or high-risk markets. At the end of triage, document a preliminary decision: investigate internally, refer the matter to another function, conduct a targeted review, or close it because the available information does not support further action. A decision to close should still state the rationale and identify any control weakness that needs attention. Build an evidence-led investigation planA written investigation plan keeps the inquiry focused and prevents selective fact-gathering. Define the allegations to be tested, the period under review, relevant locations and systems, responsible investigators, decision-makers, applicable policies, and expected milestones. Separate the questions clearly: what happened, who authorized or benefited from it, how it was concealed, what loss occurred, and whether controls failed. Identify likely evidence before contacting the subject. Sources may include accounting entries, invoices, purchase orders, approval logs, emails, messaging records, access logs, expense claims, contracts, vendor due diligence, bank information, inventory records, and meeting notes. A legal or forensic specialist should advise on collection methods where evidence may need to be used in litigation, disciplinary proceedings, or a regulatory report. Preserve data in a defensible manner. Record the source, custodian, date collected, method used, and any transformations made. Do not casually edit files, forward sensitive material to personal accounts, or rely on screenshots when original records are available. Digital evidence may require forensic imaging, metadata preservation, keyword searches, or assistance from information security.
Develop an evidence matrix linking each allegation to the facts needed to prove or disprove it. For example, an allegation of inflated supplier invoices may require evidence of the agreed price, delivery, approval, relationship between the parties, payment destination, and any communication showing intent. This method helps investigators distinguish missing evidence from evidence that contradicts the allegation. Conduct interviews and test the factsInterviews should generally proceed from background witnesses and process owners to people with direct knowledge, and finally to the subject of the allegation. This sequence can reveal terminology, transaction flows, and documentary leads before the subject is asked to explain suspicious conduct. The order may change if there is a serious risk that a witness will coordinate accounts or destroy evidence. Prepare an interview outline, but allow relevant facts to emerge naturally. Start with open questions such as “Please describe how this supplier was selected” before moving to specific documents and discrepancies. Ask about dates, decisions, authorizations, relationships, and alternatives considered. Avoid aggressive language, promises of confidentiality that cannot be kept, or questions that assume misconduct. Give the subject a meaningful opportunity to respond to the material concerns. Present enough detail to obtain a useful explanation while protecting confidential sources and the integrity of the investigation. Ask whether there is another explanation, another person who can clarify the issue, or additional documentation that should be reviewed. A fair process does not require investigators to accept every explanation, but it does require them to test plausible alternatives. Document interviews promptly and accurately. Depending on local law and policy, the record may be a signed statement, investigator notes, or an approved transcript. Record significant questions, answers, exhibits, and follow-up actions. If an interview is recorded, obtain any required consent and store the recording securely. Translation should be provided where language differences could affect the reliability of the account. Reach a defensible findingAnalyze evidence against the organization’s defined standard of proof and relevant policy language. Many internal investigations use a balance-of-probabilities approach, meaning the evidence makes one explanation more likely than another. Some jurisdictions, contracts, or regulatory processes may require a different standard. The report should state the standard used rather than leaving the decision-maker to infer it. Assess credibility systematically. Consider whether a witness had direct knowledge, whether the account remained consistent, whether it was supported by independent records, whether the person had a motive to mislead, and whether the explanation fits the chronology. A confident witness is not necessarily a reliable witness, and a nervous or imperfect account is not automatically false. Separate findings about conduct from findings about controls. The evidence may substantiate unauthorized payments but fail to establish who benefited. It may show that an employee breached a purchasing policy without proving an intent to defraud. It may also reveal that several people followed an ambiguous process. Clear categories such as substantiated, unsubstantiated, inconclusive, or outside scope can make the outcome easier to apply consistently. The final investigation report should summarize the mandate, methodology, evidence reviewed, interviews completed, factual chronology, analysis, findings, financial impact, policy implications, and unresolved limitations. Keep conclusions proportionate to the evidence. If a report may be shared with regulators, auditors, insurers, or courts, legal counsel should review privilege, disclosure, and jurisdictional issues before distribution. Remediate, report, and monitorOnce findings are approved, determine the appropriate response. Options may include recovery of funds, disciplinary action, contract termination, strengthened approvals, enhanced due diligence, system changes, training, or referral to law enforcement or a regulator. Decisions should be consistent with policy, employment law, past practice, and the seriousness of the conduct. Seniority should not shield an employee or business partner from accountability. Consider whether disclosure is mandatory or advisable. Reporting duties can arise under anti-bribery laws, financial regulations, market rules, grant conditions, insurance policies, contractual terms, or obligations to financial institutions. Legal counsel should assess timing, content, privilege, self-reporting incentives, and the risk that an incomplete disclosure creates further exposure. Recovery and remediation should be tracked as formally as the investigation itself. Assign each action to a named owner, set a deadline, and define evidence of completion. If the fraud involved a supplier or intermediary, review onboarding, beneficial ownership checks, payment controls, conflict declarations, invoice verification, and monitoring. A control that failed because of a single override may need a different response from a control that was absent across the business. Controls that reduce repeat incidents
Close the case only after corrective actions, communication decisions, and record-retention requirements are addressed. Where appropriate, share anonymized lessons with employees and relevant control owners. Communicating that a concern was reviewed and that safeguards were strengthened can reinforce trust without disclosing personal information or compromising legal obligations. A disciplined internal fraud investigation protects more than the organization’s money. It supports fair treatment, reliable financial reporting, ethical business relationships, and credible compliance oversight. Use a documented procedure, preserve evidence early, test every material explanation, and turn each substantiated concern into measurable control improvement. Begin by reviewing your reporting channels and investigation protocol, then assign owners and deadlines for the safeguards that matter most. |