When a client calls me about a fraud concern, the conversation rarely begins with certainty. It begins with a feeling — something that does not add up, a pattern that has resisted explanation, a concern raised by a colleague that seems credible but cannot yet be substantiated. My job in that first conversation is not to confirm what happened. It is to understand what is known, what is suspected, and what the organisation is trying to achieve — and then to begin structuring a response that preserves options rather than foreclosing them.
Corporate fraud investigations are not a single, standardised process. Every case has its own configuration: different actors, different methods, different evidence sources, different legal and commercial objectives. What remains consistent is the discipline with which the investigation is structured, the care with which evidence is gathered and preserved, and the independence that gives the findings credibility when they are tested.
This article sets out how a corporate fraud investigation actually works — from the initial risk assessment through to the support we provide in legal proceedings. It is intended for boards, legal teams, private equity professionals, and family office advisers who are either facing a fraud concern now or want to understand what engaging an external investigator involves before they need to make that decision under pressure.
What Is a Corporate Fraud Investigation?
A corporate fraud investigation is a structured, independent enquiry into suspected fraudulent conduct within or affecting a business organisation. It is distinct from an internal audit, a compliance review, or a management investigation in several important respects: it is conducted by professionals with investigative independence from the organisation, it applies forensic standards to the collection and handling of evidence, and it is designed to produce findings that will hold up to scrutiny in legal proceedings if required.
The scope of conduct that falls within corporate fraud is broad. It includes asset misappropriation, financial statement fraud, procurement corruption, payroll manipulation, director misconduct, supplier fraud, invoice fraud, money laundering, and the full range of schemes I have described across the other articles in this series. What these cases share is the element of deliberate dishonesty within or directed at a corporate entity — and the need for a response that is more rigorous than an internal review can provide.
The organisations that instruct us span a wide range: FTSE-listed companies, private equity-backed businesses, family offices, international law firms acting for corporate clients, and owner-managed businesses that have identified a concern and need external expertise to address it properly. The scale of the case and the complexity of the conduct vary considerably. The principles that guide how we work do not.
Initial Risk Assessment
The initial risk assessment is the most consequential stage of any corporate fraud investigation. What is decided here — about the scope of the concern, the individuals involved, the immediate evidence preservation priorities, and the governance of the investigation itself — shapes everything that follows. Getting it right matters considerably more than getting it fast.
In practice, the first substantive step is a structured assessment of what the organisation knows, what it suspects, and what gaps exist between the two. I approach this through a series of questions that I have refined over many years of working on these cases:
- What is the specific nature of the suspected conduct, and what evidence currently exists to support the concern?
- Who are the individuals potentially involved, and what is their level of access to systems, funds, and documentation?
- What is the most likely outcome the organisation is working toward: disciplinary action, civil recovery, criminal referral, regulatory notification, or a combination?
- Is there a conflict of interest that makes internal management of the investigation inappropriate or unreliable?
- Are there any immediate steps required to prevent further loss, to preserve evidence that is at risk of deletion or removal, or to restrict access by individuals under suspicion?
- Should the investigation be structured under legal professional privilege, and if so, what does that require in terms of the instructing relationship?
That last question matters more than it might appear. If legal proceedings are a probable outcome — which in a serious fraud case they almost always are — structuring the investigation under privilege from the outset protects the work product from disclosure. The decision needs to be made before the investigation begins, not after. I work through this with the instructing solicitors at the outset of every significant engagement.
The risk assessment also identifies whether there are any immediate operational risks that need to be managed before the investigation proper begins: a director with the ability to move assets, an employee with system access that could be used to destroy evidence, or a third party whose involvement creates a disclosure risk if the investigation becomes visible prematurely. Addressing those risks quietly and without alerting anyone under suspicion is often the most practically demanding part of the initial stage.
Planning the Investigation
Once the risk assessment is complete, the investigation is planned in detail before any overt step is taken. This is a discipline I am consistent about, because the pressure to act visibly — to be seen to be doing something — is real in fraud cases, and acting without a plan consistently produces worse outcomes than taking the time to think carefully about what needs to happen and in what order.
The investigation plan sets out the scope of the enquiry, the evidence sources that will be examined, the sequence in which investigative steps will be taken, the individuals who will be interviewed and in what order, the governance structure — who receives updates, who has authority to act on findings — and the timeline. It is a working document that will be revised as the investigation develops and new information emerges. But having a plan means that revisions are deliberate responses to new evidence rather than reactive lurches in a different direction.
The planning stage also addresses the covert preliminary phase that precedes any overt action. In most corporate fraud investigations, there is a period of background enquiry before anyone with potential involvement becomes aware that an investigation is underway. How long that phase runs, and what it covers, depends on the specific case. What I am consistent about is that overt steps — interviews, system access restrictions, document requests — do not happen before the covert preliminary work has built sufficient evidential foundation to justify them.
Evidence Gathering
Evidence gathering is the operational core of a corporate fraud investigation, and it is where the quality of the investigation is most directly determined. The objective at every stage is to collect material that is accurate, complete, and gathered in a manner that will withstand challenge — whether in a disciplinary hearing, an employment tribunal, a civil court, or a criminal prosecution.
The principle I apply to evidence gathering is that methodology matters as much as content. A document that proves the fraud occurred is not useful if it was collected by someone without the authority to access it, handled without a chain of custody record, or obtained in a manner that creates its own legal exposure for the organisation. Evidence gathered carelessly does not just weaken the case. It can actively damage it.
In practice, evidence gathering in a corporate fraud investigation draws on several distinct disciplines, which I will address in turn.
Digital Forensics
The majority of corporate fraud investigations now have a substantial digital component. Financial transactions, communications, approval workflows, access logs, document histories — most of the activity relevant to a corporate fraud enquiry passes through or is recorded in digital systems. The ability to recover, preserve, and analyse that material forensically is central to how these cases are built.
When I refer to forensic digital evidence collection, I mean something specific: the creation of verified, bit-for-bit images of relevant devices and storage locations, using tools and processes that preserve the integrity of the original material and maintain an auditable record of everything that was done to it. This is not the same as copying files. Standard file copying alters metadata, does not capture deleted material, and produces a record that cannot be independently verified. Forensic imaging does none of those things and is the only approach that produces digital evidence capable of withstanding challenge in proceedings.
Email and messaging archives: communications between the individuals under investigation, between those individuals and external parties, and between the relevant functions and senior management are frequently the most direct evidence of intent and arrangement. Deleted emails are often recoverable from server archives, backup systems, or device images. People are generally less aware of this than they think, and the emails they believed they had removed are often the most significant material in the investigation.
Financial system audit trails: accounting and ERP platforms log every transaction, every change, every approval, and every access event, with timestamps and user identifiers. These logs are objective, difficult to manipulate without leaving a further record, and routinely overlooked in internal reviews. In my experience they are among the most reliable evidence sources in any corporate fraud investigation.
Document metadata: the creation date, modification history, and authorship data embedded in digital documents can confirm or directly contradict the accounts given by individuals under investigation. I have seen cases turn on metadata that established a document had been created weeks after the date it purported to bear.
Access logs and device activity: system access logs establish who was using which accounts, from which devices, at what times. In fraud cases involving unusual after-hours activity, access from unexpected locations, or the use of shared credentials to obscure individual responsibility, these logs are often determinative.
Cloud storage and file transfer records: where data theft accompanies financial fraud — which is more common than organisations assume — evidence of files being moved to personal storage or shared externally is typically visible in platform audit trails and network logs.
All digital evidence collection is conducted in compliance with UK GDPR, the Investigatory Powers Act 2016, and the Regulation of Investigatory Powers Act 2000. Employer monitoring of devices and systems is lawful in the UK subject to proportionality and the organisation’s stated policies. Legal advice on the scope of any monitoring activity is obtained before it begins — not after.
Financial Analysis
Financial analysis is the discipline through which the evidential significance of what the digital and documentary evidence contains is established. Identifying that a payment was made is not the same as understanding why it was made, whether it was authorised, whether it was at arms-length, and whether it fits a pattern that is consistent with fraud. That analytical work requires both forensic accounting capability and investigative understanding of how fraud schemes are structured and sustained.
The financial analysis in a corporate fraud investigation typically covers:
Transaction analysis: a systematic review of payment records, invoice data, and accounting entries to identify anomalies — unauthorised transactions, duplicate payments, threshold structuring, pricing irregularities, and entries that lack the authorisation or supporting documentation they should have.
Variance analysis: a comparison of reported figures against underlying operational data, budget expectations, and prior period performance. Fraud that is sustained over multiple periods tends to leave a characteristic pattern in the variance data: consistently one-directional, disproportionate to business factors, and resistant to explanation through normal commercial activity.
Financial reconstruction: in cases involving false accounting or financial statement manipulation, a restatement of the financial records applying correct treatment to identified manipulations, to establish what the true position was and to quantify the difference between that position and what was reported.
Asset tracing: in cases where funds have been diverted or assets misappropriated, a forensic tracing of the flow of funds to identify where they went, what entities or accounts they passed through, and whether any recoverable assets can be identified in support of a civil recovery claim.
Lifestyle and income analysis: where the concern involves an individual whose lifestyle appears inconsistent with their disclosed income, a structured comparison of known expenditure and asset acquisition against declared remuneration, used as a framework for identifying unexplained wealth that may indicate the scale of undisclosed receipts.
The financial analysis does not produce conclusions in isolation. It produces a structured set of findings that, combined with the digital evidence, the documentary record, and the witness accounts, builds the complete evidential picture that the investigation report will present.
Witness Interviews
Witness interviews are the point at which the investigation moves from examining records to understanding what the people involved knew and did. They are also the stage that carries the greatest legal risk if handled incorrectly, and the stage where the independence of the investigator matters most directly.
The sequencing of interviews in a corporate fraud investigation is not a logistical question. It is strategic. The principle I follow is consistent: work from the outside in. Interview those with peripheral knowledge first — colleagues who may have observed relevant behaviour, finance staff who processed transactions without understanding their significance, operational managers whose records are relevant to the enquiry. Build the picture progressively. Reach the primary subject last, when the evidential framework is as complete as possible and the questions can be precise rather than exploratory.
For interviews to be legally defensible, several requirements apply without exception:
- Every interviewee must be clearly informed of the purpose of the interview and their rights, including the right to be accompanied in a disciplinary context under the Employment Relations Act 1999.
- The interviewer must have no personal stake in the outcome and no prior relationship with the subject that would compromise the neutrality of the process.
- A verbatim record must be maintained, either through contemporaneous notes or, where agreed, recording. The record is provided to the interviewee for review and challenge.
- Questions must be factual and open, not leading. The difference between an open question and a leading one is not stylistic — it is the difference between a finding that holds up and one that gets taken apart.
- Where the interview forms part of a formal disciplinary process, the ACAS Code of Practice on Disciplinary and Grievance Procedures applies in full and must be followed.
The credibility of interview findings is directly related to the independence of the interviewer. An internal manager conducting an investigation interview with a colleague, however well-intentioned, is in a fundamentally different position from an external investigator with no prior relationship with the organisation, no stake in the commercial outcome, and no reason to prefer one account over another. That difference matters in disciplinary proceedings. It matters considerably more in litigation.
Surveillance Techniques
Covert surveillance is not a default tool in corporate fraud investigations. It is a specific capability that becomes relevant when other evidence sources cannot establish facts that are material to the investigation — typically, facts about an individual’s physical activities, external relationships, or conduct outside the organisation’s systems and records.
The circumstances in which I consider surveillance appropriate include: confirming an undisclosed secondary employment or competing business activity, establishing the physical reality of a claimed relationship between an employee and a supplier, documenting conduct that the subject has denied and that no digital record captures, and verifying the asset and lifestyle picture that supports a financial analysis of unexplained wealth.
Surveillance in England and Wales must comply with the Regulation of Investigatory Powers Act 2000, UK GDPR, and the Human Rights Act 1998. The tests are necessity and proportionality: is the surveillance genuinely required to achieve a legitimate investigative objective, and is the degree of intrusion proportionate to that objective? Those tests apply to every surveillance decision, and they are applied before the activity begins, not after.
The methods available include:
Physical surveillance: covert observation of the subject’s movements, meetings, and activities by trained investigators operating within the legal framework. The purpose is to establish facts that cannot be documented through any other available evidence source.
Open source intelligence (OSINT): a systematic review of publicly available information — company filings, social media, property records, professional registrations, litigation history — to identify undisclosed interests, assets, relationships, and activities. OSINT is not surveillance in the traditional sense, but it is frequently the most productive source of intelligence in the early stages of an investigation, and it is entirely lawful.
Vehicle and location data: where a company vehicle is involved, tracking data may already be available under the organisation’s monitoring policy. For personal vehicles, specific authority is required before any tracking activity takes place.
Surveillance conducted without proper authority is not simply inadmissible. It creates civil liability and regulatory exposure for the organisation that instructed it. This is one of the clearest reasons why surveillance activity in a corporate fraud investigation should be conducted by professional investigators who understand the legal framework, not by internal staff acting on their own initiative.
Reporting Findings
The investigation report is the point at which everything the investigation has produced either holds together as a coherent, evidentially grounded account — or it does not. I have written a significant number of these reports over the course of my career, and the discipline I apply to every one is the same: the report must be usable. Not just accurate. Usable — by a board, by legal counsel, by a disciplinary panel, by a court.
A report that cannot be used is worse than no report at all. It creates the impression of a concluded investigation without providing the foundation for action, and it is the kind of document that opposing counsel will take apart systematically if proceedings follow. The standards I apply are:
- The terms of reference are stated precisely: what the investigation was asked to establish, what it was not, and any limitations on scope that affected the findings.
- The methodology is described in sufficient detail that an independent reader can assess whether the approach was sound and the evidence was handled correctly.
- The evidence is presented factually and chronologically, without editorial commentary. The facts do the work.
- The report distinguishes explicitly between what is established by direct evidence, what is established by inference, and what remains unresolved.
- Limitations are acknowledged honestly: evidence that could not be obtained, witnesses who declined to participate, areas where the picture is incomplete.
- Conclusions are proportionate to the evidence. The report does not attribute criminal conduct unless a court has determined it. The correct framing is that the evidence is consistent with, or supports a conclusion of, the specified conduct.
- The report is written with full awareness of who will read it and in what context. If it is likely to be disclosed in proceedings, it is written accordingly from the first draft.
The most dangerous investigation report is one that overstates. A finding that reaches further than the evidence supports is the one that gets challenged, and a successful challenge to the findings takes the credibility of the entire investigation with it. Precision and intellectual honesty are not caution. They are what makes the report genuinely useful.
Supporting Legal Proceedings
A corporate fraud investigation rarely ends when the report is delivered. In most cases of any scale, the findings feed directly into one or more legal processes — disciplinary proceedings, civil litigation, criminal referral, regulatory engagement, or some combination — and the investigation team’s role continues through that process.
Disciplinary proceedings: the investigation findings provide the evidential basis for any disciplinary process, and I regularly attend disciplinary hearings to present findings and respond to challenges from the subject or their representative. The ACAS Code applies, and the investigation’s compliance with that framework will be scrutinised. Independence and documentation are the foundations of a defensible process.
Civil litigation: where civil proceedings follow — for breach of fiduciary duty, asset recovery, or damages — the investigation report and the underlying evidence become part of the litigation bundle. I work closely with the instructing solicitors on the preparation of witness statements, the management of disclosure, and the presentation of the financial analysis. Where the case goes to trial, I may give expert evidence on the investigative findings or the financial reconstruction.
Freezing injunctions and interim relief: where the risk of asset dissipation is immediate, the investigation findings can support an urgent application for a freezing injunction. The speed and quality of the evidential foundation are critical: applications need to be made on notice or, in urgent cases, without notice, and the supporting evidence needs to meet the legal threshold for the relief sought.
Criminal referral: where the findings support a criminal referral, I assist the legal team in presenting the evidence to the relevant authority in a form that is accessible and actionable. Different authorities — the police, Action Fraud, the Serious Fraud Office — have different thresholds and different processes. Understanding how to engage with each is part of what I bring to this stage.
Regulatory engagement: in regulated sectors, the investigation findings may inform a mandatory or voluntary disclosure to the FCA, the SRA, or another relevant body. The content and timing of that disclosure, and the manner in which the investigation’s findings are presented, can significantly affect the regulatory response. I work alongside legal advisers on this, providing the factual and evidential foundation for the disclosure rather than making the disclosure itself.
Why Businesses Use External Investigators
I am sometimes asked why an organisation with an internal audit function, an HR team, and legal advisers would need to bring in external investigators. It is a reasonable question, and the honest answer is that not every fraud concern requires it. Where the suspected conduct is genuinely limited in scope, involves a junior employee, and does not create any conflict of interest for the internal team, internal resource may be adequate.
In my experience, however, the cases that initially appear contained rarely stay that way. The following are the circumstances in which external investigators consistently produce better outcomes than internal processes:
- The suspected individual is a senior employee, director, or someone whose involvement creates an obvious conflict for internal management or the audit function.
- The evidence base is primarily digital and requires forensic-quality collection and handling.
- The investigation may lead to legal proceedings, meaning the independence and documented methodology of the process will be scrutinised.
- There is a real risk that an internal investigation will be compromised by the subject becoming aware of it, through their access to systems, relationships with colleagues, or position in the organisation.
- The organisation has attempted an internal investigation that has stalled, produced challenged findings, or been compromised in a way that requires an independent restart.
- The scale of the potential loss or reputational exposure makes the quality of the investigation outcome genuinely material to the organisation’s interests.
- The cross-border or multi-jurisdictional dimension of the conduct exceeds the expertise and reach of internal teams.
Beyond the specific circumstances, there is a more fundamental consideration. An investigation conducted by external professionals with no prior relationship with the organisation, its people, or its commercial interests carries a credibility and an independence that an internal process cannot replicate — however well-intentioned. That independence is not just a legal nicety. It is the foundation on which the investigation’s findings can be built, challenged, and ultimately relied upon.
At iSpy Detectives, we work with organisations at every stage of a fraud concern: from the first confidential call to understand what they are dealing with, through the full investigation, and into the legal proceedings that follow. The quality of what we deliver is measured not by what we find, but by whether what we find can be used.
Dealing with a fraud concern and unsure where to start? Book a confidential consultation with our corporate investigations team. Our team has recently corporate fraud investigations for corporate clients in London, Cardiff, Liverpool, Nottingham, Aberdeen, Rochester and Sheffield.
Related Services
For organisations dealing with specific forms of corporate fraud, the following pages in this series may be relevant:

