SKIP TO CONTENT
MATTER TYPE / INVESTIGATIONS

Internal and government investigations: scope, privilege, and the audience you do not have yet

An investigation is defined by two decisions taken before any evidence is read — how wide preservation goes, and how privileged material is kept away from the investigative team. Both are made under time pressure with an incomplete picture, both are reviewed later by people who know how it turned out, and both are judged on what was written down at the time.

QUESTION
What happened, and what must be kept
CORE RECORDS
Audit log · sign-in · EDR · mail
CLOCK
Volatile sources roll off in days
USUAL POSTURE
Board · regulator · parallel civil
DELIVERABLE
Findings, then a Rule 26 report
ROLES
Consulting · Testifying · Neutral
IN SHORT

In an internal or government investigation the forensic record normally establishes what systems and accounts did, what was retained and what the retention settings would have removed, and whether the privilege protocol was actually followed. It does not establish whether conduct broke a rule or a law, that a collection was complete, or that privilege was never breached — only that the protocol was applied and logged, which is a different and provable thing.

What is actually in dispute

An investigation has two subjects running at once — the conduct being investigated, and the investigation itself — and the second one is frequently what gets litigated.

The conduct question varies: a whistleblower complaint, a trading allegation, an export control review, a payment nobody can explain, a subpoena that names four custodians and implies eleven. The investigation question does not vary. Was preservation adequate and timely. Was the collection proportionate to what was known. Was privileged material kept from people who should not have seen it. Can the findings be reproduced by someone who was not there.

Those second-order questions are the reason forensic discipline matters here more than the subject matter does. An examination that is sound but undocumented answers the first question and fails the second, and it fails it in front of an audience — a regulator, a court, a board committee, an adversary in parallel civil litigation — that was not in contemplation when the work was scoped.

Scope is the irreversible decision

Preservation and collection are often discussed together and behave very differently. Suspending deletion across a wide custodian population costs storage and inconvenience and can be narrowed later. Collecting from that population creates a review population, a privilege problem, a data protection problem where custodians sit in other jurisdictions, and a set of material that now exists and is discoverable. The workable sequence is therefore to preserve broadly, capture the volatile sources at once, and collect in stages against a written scope that records what was known at each step.

The volatile sources are the exception to staging, because they do not wait. Endpoint detection telemetry is retained on a licence tier measured in days on many platforms. Cloud audit records roll off on a schedule set by tenant configuration years ago. Memory is gone when the machine is restarted, and a laptop reissued to another employee has overwritten most of what mattered.

Which records bear on it

Investigations are usually enterprise matters, so the centre of gravity is server-side and tenant-side rather than on any one device. Endpoint work is targeted at custodians the enterprise records already point to.

Tenant and identity

The Microsoft 365 unified audit log records mail, file, sharing, administrative and policy operations across the tenant, and it is normally the backbone of an investigation of this kind — subject to a retention window that depends on licence and configuration. Entra ID sign-in logs record authentication with application, device, address and conditional-access outcome, and administrative audit records show changes to roles, policies and mailbox permissions — including changes made during the investigation.

Endpoint and security stack

EDR telemetry and process creation events record execution with command lines and parent processes; endpoint protection logs record detections and, importantly, exclusions somebody configured; and logon events supply the authentication half on the device side. SRUM records per-application network volume in hourly buckets, which is frequently the only local measure of how much data left a machine.

Movement of data

Sync client records, browser downloads and removable device history answer the exfiltration limb where one exists. Data loss prevention and mail gateway records add the enterprise view, and where the investigation concerns an intrusion rather than an insider, the same sources support the incident reconstruction described on the server forensics page.

Limits of proof

What this evidence cannot establish

  • Whether the conduct broke a rule or a law. An examiner establishes what systems and accounts did. Whether that was a policy violation, a securities offence, an export breach or nothing at all is the assessment counsel and the regulator make, and an expert who states it has left the discipline for the one place a tribunal is watching.
  • That the collection was complete. Collections proceed from a custodian list and a systems inventory, both of which are human products assembled under time pressure. A shadow system nobody mentioned, an account outside the tenant, a personal device — the examination reports what was collected and from where, and completeness is a claim about the inventory rather than about the evidence.
  • That privilege was not breached. What can be shown is that a defined protocol was applied, that the segregated set was isolated, and that the access log records who could reach what. Absolute assurance is not available, and a report offering it is claiming something the logs do not carry.
  • Who was behind a shared or service account. Administrative and service credentials are used by several people and by automation, and elevated access is precisely where investigations concentrate. Attribution needs corroboration from outside the systems, and often none exists.
  • What deleted material contained, or why it went. A deletion outside the ordinary retention schedule is a finding worth stating precisely and dating carefully. What was in the deleted material, and whether anyone intended to obstruct anything, are not things the record establishes.

Where the dispute is about the discovery process itself — ESI protocol negotiation, search-term validation, technology-assisted review — that is covered at ediscoveryexpertwitness.com. Where a court appoints a neutral to supervise the examination, technicalspecialmaster.com sets out that role, and where an incident has moved into breach negotiation, databreachmediator.com covers it.

The expert’s role and the deliverable

  1. Write the preservation scope down, then issue it. A litigation hold naming custodians, systems and date ranges, with automatic deletion suspended and the reasoning recorded. The preservation deadline calculator sets out how fast the common sources age out, and the volatile ones are captured the same day rather than staged.
  2. Establish the privilege protocol before the first collection. Who reviews, in what order, behind which wall, with what filtering, and how access is logged. Designed after collection has begun, a protocol is a remediation; designed before, it is a defence.
  3. Collect forensically even when nobody has sued. Hashes at acquisition and verification, custody records, exports whose queries and date ranges are recorded so the collection can be repeated. The cost difference against an informal copy is small; the difference in what the material can later be used for is not.
  4. Keep the analysis reproducible and the notes disciplined. Every search, filter and tool version recorded, so a finding can be re-derived by someone who was not in the room. Interim material in an investigation is frequently produced later, and it should read as work that expected to be.
  5. Report to the audience present, at the standard of the audience to come. A board briefing and a regulator submission look different and should rest on the same examination. The rule that makes that possible is simple: nothing in the briefing that the underlying record does not support.
  6. Testify, where the matter goes that way. A consulting examination becomes a Rule 26(a)(2)(B) disclosure when a testifying role is taken up, and the transition is far easier where the work was documented as though it would be. How that report is scoped and defended is set out on the expert witness testimony page.

Where the pressure falls here

Some of this work never reaches a courtroom, and the standards applied to it are no softer for that. A regulator asks how the conclusion was reached; a board committee asks what it rests on; and if a civil action follows, Rule 702 as amended on December 1, 2023 asks whether the opinion reflects a reliable application of the method to the facts of the case. The failure modes are shared.

  • Scope limits that were never disclosed. An investigation that examined four custodians out of a population of forty reached a defensible conclusion about four custodians. Where the report does not say so, the omission is what the cross-examination is about.
  • Privilege screening that cannot be evidenced. A protocol nobody logged is indistinguishable, months later, from a protocol nobody followed. The access record is what converts an assertion about the wall into a fact about it.
  • Preservation gaps discovered by the other side. Retention settings, hold dates and deletion events are all establishable facts. Establishing them yourself, early, is a different posture from having them established for you at a sanctions hearing.
  • A board deck offered as an expert opinion. Investigation summaries are written to be read quickly, with confident headline findings and the qualifications compressed out. Repurposed as expert evidence, the compression is the problem, and the underlying work usually deserved better.
  • Legal conclusions in a technical report. “Unauthorised”, “misappropriated”, “fraudulent” and “in violation of” are characterisations, not findings. Removing them costs nothing and removes the easiest available attack.
RECORDWHAT IT ESTABLISHESWHAT IT DOES NOT ESTABLISH
Microsoft 365 unified audit logMail, file, sharing and administrative operations across the tenant, with actor, target and timeContent of the items acted on, and anything outside the retention window the licence and configuration set
Entra ID sign-in logsAuthentication with application, device, address and conditional-access outcomeThe person behind the credential, or the physical location of the session
Administrative and policy change recordsChanges to roles, permissions, retention and mailbox delegation — including changes made after the investigation beganWhy a change was made, or whether it was authorised by anyone with the standing to authorise it
EDR telemetry and process creation eventsExecution with command lines and parent process, across covered endpointsThat an endpoint was covered at all on the date in question, and retention is frequently measured in days
Endpoint protection logsDetections, quarantines, and the exclusions somebody configured — which are often the more interesting entryThat nothing malicious ran. Detection depends on signatures, coverage and configuration
Retention and hold configurationWhat the deletion schedule was, when a hold was applied, and which custodians and systems it reachedWhat was lost before the hold. Absence within a rolled window is not evidence of deletion
Privilege review access logsThat a defined protocol was applied and which reviewers could reach the segregated setThat no privileged material was ever seen by anyone outside the wall
The right-hand column is where these opinions are attacked, whether the audience is a court, a regulator or a board. Each record above has its own page under /artifacts setting out retention, failure modes, and how a finding drawn from it is challenged.

Questions counsel ask

How wide should the preservation scope be at the start?

Wider than the collection and narrower than everything, and decided before either. Preservation is reversible and cheap; collection is expensive and creates review, privilege and production exposure. The usual approach is to suspend automatic deletion for a defined custodian population and the systems that touch the conduct, capture the volatile sources immediately because they will not wait, and then collect from that preserved set in stages as the picture narrows. The scope and the reasons for it are written down at the time, because the adequacy of the decision is judged later on what was known when it was made.

What does the forensic examiner do about privilege?

Usually the mechanical half of a protocol counsel designs. That means building the collection so privileged material can be segregated before the investigative team reaches it — custodian and date filtering, counsel-domain and name searches, isolation of the segregated set, and an access log showing which reviewers could reach what and when. Where a walled-off review is in place the examiner often supports it on both sides of the wall, and the value of the arrangement lies almost entirely in the documentation that shows it held.

Employees are being interviewed. Does that affect the forensic work?

It shapes it. An Upjohn warning tells the employee that counsel represents the company rather than them, that the conversation is privileged to the company, and that the company may waive that privilege — and a forensic examiner working alongside those interviews sits inside the same structure. In practice it means being clear about who instructs the examiner, keeping employee personal data separated from company data when a personal device is in scope, and not becoming an informal channel between the investigative team and the custodian.

The investigation was for the board. Now a regulator wants the findings. Is that a problem?

It is a foreseeable outcome that shapes how the work should have been done. An internal investigation frequently becomes a presentation to a regulator, a self-report, a production in civil litigation, or the record behind a criminal referral, and each audience applies a different standard to the same underlying examination. Work built to the evidentiary standard from the outset — sound acquisition, hashes, custody records, reproducible analysis, opinions that trace to named artifacts — survives that transition. Work built only to brief a committee generally does not.

Can you examine an employee's personal phone or laptop?

Only on a basis counsel has established, and the arrangement matters. Consent from the device owner, the scope of the company's own bring-your-own-device policy, and the terms of any preservation obligation all bear on it. Where personal devices are in scope, the workable approach is usually a targeted collection of defined containers rather than a full image, with the scope agreed in writing beforehand — and where the material is on a phone, extraction is a separate acquisition discipline covered on a sibling site.

What happens if data was already lost before anyone acted?

It becomes its own line of enquiry rather than a dead end. What can normally be established is what the retention configuration was, when automatic deletion would have removed the material, whether a hold was applied and when, and whether anything was deleted outside that ordinary schedule. Those are findings about the record-keeping, and they are what a court or a regulator asks about when the question of preservation failure arises. Whether the loss amounts to spoliation, and what should follow from it, is not a forensic question.
  • Cloud forensics

    Tenant audit logs, retention windows, API-only collection, and what a cloud provider does and does not keep on your behalf.

  • Server forensics

    Domain controllers, application and access logs, and the reconstruction of activity across systems rather than on one device.

  • Employment and departing employees

    Where an internal investigation concerns one custodian's access — account-versus-person attribution, and authorisation scope.

  • How to hire and vet a forensic expert

    Consulting versus testifying versus court-appointed, what to demand before retention, conflicts, timing, and cost.

ENGAGE AN EXPERT ON AN INVESTIGATION

Endpoint telemetry rolls off in days, tenant audit retention was set years ago by someone who has left, and the preservation decision is judged later on what was written down at the time. Send the matter, the regulator or forum if there is one, the custodian population, and where the systems sit — a conflicts check and a scoping call follow.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

Attorney advertising / expert services. This page describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Prior results do not guarantee a similar outcome.