
The first 48 hours after a corporate fraud suspicion surfaces determine whether the loss is recoverable: lock down access and records before anyone is confronted, route the matter through counsel to preserve privilege, and engage an independent investigator instead of well-meaning internal staff. Move too fast toward accusation and the subject destroys evidence or resigns with the money; move too slow and the trail goes cold. This guide is the operational sequence — not a service brochure — for boards, general counsel, and executives who suspect fraud right now.
Most companies encounter fraud exactly once or twice in a leadership tenure, and it is almost never handled by people who have done it before. That inexperience is the single biggest reason internal responses fail: the controller who “just wants to ask a few questions,” the HR director who pulls a personnel file before legal hold is issued, the CFO who quietly fixes the numbers rather than reporting them. Every one of those instincts feels responsible. Every one of them can spoil the evidence, waive privilege, or tip off the person responsible. This guide lays out the sequence a disciplined investigation actually follows, from the moment suspicion arises to the moment a case is closed, recovered, or referred.
What are the red flags that justify opening an investigation?
Fraud is rarely discovered through a smoking-gun document. It surfaces through a pattern that, individually, each person dismisses — and collectively, should not be ignored. The Association of Certified Fraud Examiners’ Report to the Nations consistently finds that tips from employees, customers, and vendors detect more occupational fraud than audits, controls, or accident combined. A credible tip line and a willingness to act on an uncomfortable pattern matter more than any single control.
- Lifestyle mismatch. An employee or executive living well beyond a documented salary — new property, vehicles, or travel with no disclosed outside income.
- Control override. One person able to originate, approve, and reconcile the same transaction class without a second set of eyes.
- Vendor anomalies. A vendor with a PO box address, no web presence, sequential invoice numbers, or an address matching an employee’s.
- Reluctance to take leave. An employee who has not taken vacation in years, or who insists on personally handling a process during any absence.
- Unexplained variance. Margins, reserves, or reported results that diverge from operational reality without a documented cause.
- Whistleblower tip. Any report from an employee, customer, or vendor alleging specific wrongdoing, however informal.
- Destroyed or missing records. Deleted files, wiped devices, or records that “cannot be located” once a question is asked.
One flag alone is rarely enough to justify a full investigation. Two or more, especially paired with a specific tip, should trigger the sequence below — starting with silence, not confrontation.
What should happen in the first 48 hours?
The instinct to “just ask” is the most common and most damaging mistake in the first two days. Every hour a suspected actor retains system access, a document trail can be altered or a device wiped. The sequence below is deliberately quiet.
- Say nothing to the subject. No confrontation, no “just a question,” no heads-up — even from someone who thinks they’re being helpful.
- Engage counsel first. Routing the matter through outside or in-house counsel, who then retains the investigator, is what preserves attorney-client privilege and work-product protection over the findings.
- Issue a legal hold. A written hold notice covering email, shared drives, financial systems, physical files, and relevant custodians’ devices, sent to IT and records custodians before anyone else knows an inquiry exists.
- Preserve system access logs and backups now. Backup rotation schedules can overwrite the exact window under review within days; suspend rotation on affected systems immediately.
- Restrict, don’t remove, system access. Quietly adjusting permissions (read-only, segregation) is less likely to alert the subject than an abrupt termination of access.
- Decide who else needs to know. Keep the circle to the smallest group possible — typically one board member or audit-committee chair, the general counsel, and the investigator.
- Engage an independent investigator rather than internal staff, particularly if the suspected actor is a manager, officer, or someone internal staff report to.
Every one of these steps is designed around a single principle: the evidence must be preserved and the hypothesis tested before the subject knows an inquiry exists. Once that window closes, the investigation is working with whatever survived.
Internal review, independent investigator, or law enforcement — which one?
Not every suspected irregularity needs an outside investigator, and not every matter belongs with the police on day one. The right first move depends on scale, who’s implicated, and where the matter is likely headed.
| Path | Best suited for | Key risk if used incorrectly | Preserves privilege? |
|---|---|---|---|
| Internal review | Small-dollar, clearly documented policy violations with no management involvement | Lacks independence; often reports to the person under scrutiny; weak evidentiary discipline | Rarely — no privilege absent counsel involvement |
| Independent investigator (via counsel) | Any matter involving an officer, manager, material dollar exposure, or potential litigation/regulatory/insurance exposure | Cost and time if scoped too broadly without phasing | Yes, when retained through counsel |
| Direct law enforcement referral | In-progress theft, immediate flight risk, or when the company wants prosecution as the primary objective from day one | Loses control of pace and disclosure; case may become public via court filings before internal remediation is ready | No — becomes a public record |
Most boards get the best outcome from the middle path: an independent investigation retained through counsel, run quietly to conclusion, with the decision on regulatory or law-enforcement referral made deliberately at the end — once the evidence is understood — rather than by default at the start.
Who needs to be on the investigation team?
A defensible corporate fraud investigation is rarely a one-discipline exercise. The team composition should match the suspected scheme, not a fixed template.
- Retaining counsel — controls privilege, scope, and the decision path on disclosure and referral.
- Independent investigator / forensic accountant — reconstructs transactions, quantifies loss, and tests the hypothesis against the documentary record.
- Digital forensics — images devices and email/cloud accounts defensibly, recovers deleted material, and establishes a timeline of access and activity.
- Background intelligence — maps undisclosed outside interests, related entities, and beneficial ownership tied to the subject or a vendor.
- HR liaison — handles personnel-policy mechanics without independent access to the evidentiary record.
- Audit committee or board sponsor — the single point of authority who receives findings and directs next steps.

How do interviews fit into the sequence?
Interviews come last, not first — and they proceed from the outside in. A disciplined investigator interviews peripheral witnesses and custodians of corroborating records before ever approaching the subject, so that by the time the subject is interviewed, the investigator already knows most of the answer and is testing candor rather than fishing for facts. Interviewing the subject too early — before documents are secured — is the single most common way a company loses the evidentiary advantage it had going in. The subject interview itself is typically scheduled only after: records are preserved, the timeline is reconstructed, and counsel has decided what disclosure obligations (employment, regulatory, insurance) the answers may trigger.
What does a defensible evidence record actually require?
An investigation that never leaves the boardroom still needs court-ready discipline, because the company rarely knows on day one whether the matter ends in a quiet separation, an insurance claim, a civil suit, or a criminal referral — and evidence gathered casually cannot be upgraded later. That means: a documented chain of custody for every device and record collected, forensic images taken before analysis (never working from a live system), dated and attributed interview memoranda, and a written investigative report that ties every conclusion back to a specific piece of evidence rather than a summary impression. Cutting corners here to save time is the most common reason a strong factual case becomes unusable in litigation, at trial, or with an insurer.
What should a company look for when choosing an investigation firm?
Not every investigator who can read a balance sheet is equipped to run a defensible corporate inquiry. A short qualification checklist protects the company before the engagement letter is signed.
- Independence from the company and the subject — no prior consulting relationship with anyone potentially implicated.
- In-house forensic and financial capability — not a broker who subcontracts the core work to unknown third parties.
- Documented chain-of-custody protocol — a written methodology, not an assurance.
- Experience testifying or supporting litigation — a report built only for internal reading rarely survives cross-examination.
- Clear phased scoping — a focused assessment before a full-blown investigation, so cost tracks the size of the actual problem.
- Discretion by design — remote-capable, minimal on-site footprint, and no requirement to disclose the engagement to staff who don’t need to know.
What happens after the investigation concludes?
A completed investigation produces a decision point, not an ending. Depending on findings, the company typically evaluates several parallel tracks: civil recovery against the responsible party or a complicit vendor, a fidelity/crime insurance claim (most policies require prompt notice and a proof-of-loss backed by exactly the documentation a proper investigation produces), referral to a state or federal regulator if the company is publicly traded or regulated, and a criminal referral to law enforcement or a prosecutor. These tracks are not mutually exclusive, but the order matters — insurance and civil-recovery deadlines are frequently shorter than companies expect, and a delayed notice can jeopardize coverage entirely. Counsel should map the applicable deadlines the moment the investigation confirms a loss, not after.
How much does a corporate fraud investigation typically cost, and what drives the number?
Cost is driven far more by scope discipline than by the size of the suspected loss. The core variables are: how many custodians’ devices and accounts must be imaged, how many transactions or years must be reconstructed, whether the subject is a rank-and-file employee or an officer with system-wide access, and how many downstream tracks (insurance, litigation, regulatory) the evidence must ultimately support. A phased approach — a bounded initial assessment to confirm the hypothesis and size the exposure, followed by a full investigation only if warranted — is what keeps cost proportionate. Firms that quote a single all-in number before reviewing any records are typically padding for the worst case rather than scoping to the facts.
Frequently asked questions
Should we confront the employee before calling an investigator?
No. Confrontation before evidence is preserved is the single most common way a recoverable case becomes unrecoverable — records get deleted, devices get wiped, and the subject has time to move or spend assets. Preserve first, decide on confrontation only after counsel and the investigator have reviewed what exists.
Can we use our own accounting or IT staff to investigate?
For very small, clearly documented matters with no management involvement, sometimes. Once an officer, manager, or someone internal staff report to is potentially implicated, internal staff lack the independence, and often the forensic discipline, to produce evidence that will hold up to an insurer, opposing counsel, or a regulator.
How long does a corporate fraud investigation take?
A phased initial assessment typically runs one to three weeks. A full investigation, depending on the number of custodians, transaction volume, and years under review, commonly runs six to twelve weeks before a report is finalized — longer for multi-entity or international schemes.
Do we have to report the fraud to the police or a regulator?
It depends on the company’s regulatory status, the size and nature of the loss, and applicable law — this is a legal determination, not an investigative one, and should be made with counsel once findings are in hand. Consult counsel before deciding; do not treat this guide as legal advice.
About Honeybadger Solutions
Honeybadger Solutions is an Arizona-licensed security and investigations firm delivering intelligence-led forensics, investigations, and cyber services to boards, general counsel, executives, and organizations nationwide and internationally. Digital forensics, financial investigations, cybersecurity, and background intelligence are handled in-house — not brokered to third parties — from our Arizona home command, keeping every engagement independent, discreet, and defensible.
Offices: Casa Grande (HQ), Phoenix, and Oro Valley, Arizona.
Phone: 602-725-2818
Confidential consultation: If your board or counsel suspects corporate fraud, contact us before confronting anyone — independent evidence preservation in the first hours often decides whether the loss is recovered.