top of page

When Investigations Become Liabilities.

How poor investigative governance can undermine evidential integrity, create organisational risk and turn legitimate investigation into liability.


This article examines how poor investigative governance can undermine evidential integrity, create organisational risk and turn a justifiable, legitimate investigation into a liability.


One of the services we provide to organisations includes the review of investigations undertaken by others where evidence and other material is to be relied upon to justify organisational decisions, disclosed to opposing parties, or subjected to cross examination or scrutiny.


We often find the basis for the investigation itself, and the information gathered as part of that investigation, may be justifiable.


However, weaknesses in investigative governance create doubt or concerns in the material being relied upon to defend or justify subsequent actions.  


Doubt undermines the material being relied upon.


Those weaknesses can expose an organisation to unnecessary risk and liability.



“Can we see the original, please?”


In our experience this can be the point at which an apparently straightforward investigation can cause substantial difficulties and become a source of risk.



The Investigation Is Not the Report.


Investigations frequently begin because an organisation needs to understand something, has concerns or doubt, or is required to establish fact.


The immediate requirement is often for information.


As initial information is considered there becomes a natural transition to intelligence (understand the issue) and evidence (establish fact).


Circumstances can change.


Information may become intelligence. 

Intelligence may direct investigation. 

Investigation may produce evidence. 

Evidence may ultimately have to withstand a level of scrutiny that was never anticipated when the first enquiry was made.



That is why the way an investigation is conducted from the outset matters.



What We Find When Investigations Are Reviewed.


A recurring problem is not that the investigation was dishonest, incompetent or that its conclusions were wrong.


It is that the organisation can no longer demonstrate evidential integrity and provenance in the processes used to determine subsequent actions or outcomes.


A surprisingly common example is the use of WhatsApp or similar messaging platforms as an informal operational record.


Surveillance is often utilised as a necessary, legitimate and proportionate tactic to progress an investigation. 

Surveillance operatives may post observations into a group as an operation develops. 

Images are uploaded. 

Locations are shared. 

Instructions are discussed. 

Client updates may be mixed with operational conversation. 

Information received second-hand may appear alongside observations made directly by an operative.


This group chat is the de facto surveillance log, decision log, surveillance management record, client update record and deployment record.  


A formal report is subsequently produced from it.


The report looks professional until somebody asks: “Can we see the originals, please?”


And the difficulties begin.



Does the WhatsApp group still exist?


Another practice we encounter is the deletion of these chat groups, messages or original imagery once an assignment is considered complete on, at best, the basis of confidentiality.


The group chat is deleted as a form of operational housekeeping.


That may feel tidy, but that is not managing evidence. It is deleting the very material upon which decisions, now subject to cross-examination and scrutiny, may rely.



The Illusion of Proof


Technology can make weak provenance look surprisingly convincing.

Images can display dates and times. 

Their presence does not establish when an image was actually created.


We routinely see third party apps used to place timestamps onto photographs. 

These can be easily manipulated to display any date or time.


Reports can incorporate screenshots, maps and imagery into highly professional looking documents, yet none of those things necessarily establish provenance or evidential integrity.


This distinction is becoming more relevant and important, not less.


As digital material becomes easier to produce, alter, recreate and generate, the ability to demonstrate provenance becomes vital.



Deletion Is Not Evidence Management.


There is an equally important qualification.


Good evidential practice does not mean retaining everything indefinitely.


Investigations frequently involve personal information, sensitive material and information concerning people unconnected or eliminated from initial inquiries. Data protection obligations matter.


Information must be collected for legitimate purposes, protected appropriately, retained for justified periods and securely deleted when it is no longer required.


Controlled retention and deletion under an appropriate governance framework is fundamentally different from operational material disappearing simply because somebody considers the job finished.


An organisation cannot rely on tomorrow what its investigators casually delete today.



A Clear Requirement.


The standards expected of investigations do not exist in isolation.


The Solicitors Regulation Authority’s guidance on internal investigations⁠ specifically identifies the importance of preserving available evidence from the outset, ensuring underlying documents and data are not lost or destroyed.


In the employment context, ACAS guidance on workplace investigations⁠ similarly emphasises the identification and collection of relevant evidence and the maintenance of an appropriate investigative record.


Civil proceedings bring these issues into even sharper focus. Practice Direction 31B of the Civil Procedure Rules⁠ expressly recognises electronic communications, deleted documents and metadata as electronic documents and addresses the preservation of electronic material in its native form.


Evidential preservation cannot be separated from information governance. ICO guidance on monitoring workers⁠ makes clear that collection and retention of personal information must remain necessary, proportionate and justified.


That is very different from simply deleting the operational record because the assignment has finished.


These issues extend beyond investigators, compliance and legal teams.


The UK Corporate Governance Code 2024⁠ requires boards within its scope to monitor and review their risk-management and internal-control framework. Provision 29 now requires a declaration concerning the effectiveness of material controls, including operational, reporting and compliance controls.

That assessment depends upon evidence.


An organisation cannot separate the quality of an investigation from the quality of the decisions subsequently based upon it.


If investigative material informs disciplinary action, litigation strategy, regulatory reporting, safeguarding measures, organisational controls or an assessment of corporate risk, its provenance and integrity can become part of the organisation’s wider governance environment.


The question “Can we see the original, please?” can travel considerably further than the investigation team.



Much of this article has considered circumstances in which an organisation is trying to establish what has happened.


Protective intelligence increasingly requires organisations to apply many of the same disciplines to understanding what is happening and what may happen next. 

We discuss these implications in depth in our Protective Intelligence articles.


Circumstances may vary.


Employee misconduct, fraud, corporate disputes, K&R operational support, insider threat.


Very different circumstances, but the same underlying SIS framework, adapted from specialist government intelligence, investigative and protective practice for commercial application supporting defensible decision-making and protection of client interests. 


Intelligence. Understand the problem, consider risk.


Evidence. Establish fact, consider risk.


Risk. Manage and mitigate risk throughout the process supporting defensible client decision-making.


SIS | Intelligence. Evidence. Risk.


bottom of page