Internal and government investigations: scope, privilege, and the audience you do not have yet
An investigation is defined by two decisions taken before any evidence is read — how wide preservation goes, and how privileged material is kept away from the investigative team. Both are made under time pressure with an incomplete picture, both are reviewed later by people who know how it turned out, and both are judged on what was written down at the time.
- QUESTION
- What happened, and what must be kept
- CORE RECORDS
- Audit log · sign-in · EDR · mail
- CLOCK
- Volatile sources roll off in days
- USUAL POSTURE
- Board · regulator · parallel civil
- DELIVERABLE
- Findings, then a Rule 26 report
- ROLES
- Consulting · Testifying · Neutral
In an internal or government investigation the forensic record normally establishes what systems and accounts did, what was retained and what the retention settings would have removed, and whether the privilege protocol was actually followed. It does not establish whether conduct broke a rule or a law, that a collection was complete, or that privilege was never breached — only that the protocol was applied and logged, which is a different and provable thing.
What is actually in dispute
An investigation has two subjects running at once — the conduct being investigated, and the investigation itself — and the second one is frequently what gets litigated.
The conduct question varies: a whistleblower complaint, a trading allegation, an export control review, a payment nobody can explain, a subpoena that names four custodians and implies eleven. The investigation question does not vary. Was preservation adequate and timely. Was the collection proportionate to what was known. Was privileged material kept from people who should not have seen it. Can the findings be reproduced by someone who was not there.
Those second-order questions are the reason forensic discipline matters here more than the subject matter does. An examination that is sound but undocumented answers the first question and fails the second, and it fails it in front of an audience — a regulator, a court, a board committee, an adversary in parallel civil litigation — that was not in contemplation when the work was scoped.
Scope is the irreversible decision
Preservation and collection are often discussed together and behave very differently. Suspending deletion across a wide custodian population costs storage and inconvenience and can be narrowed later. Collecting from that population creates a review population, a privilege problem, a data protection problem where custodians sit in other jurisdictions, and a set of material that now exists and is discoverable. The workable sequence is therefore to preserve broadly, capture the volatile sources at once, and collect in stages against a written scope that records what was known at each step.
The volatile sources are the exception to staging, because they do not wait. Endpoint detection telemetry is retained on a licence tier measured in days on many platforms. Cloud audit records roll off on a schedule set by tenant configuration years ago. Memory is gone when the machine is restarted, and a laptop reissued to another employee has overwritten most of what mattered.
Which records bear on it
Investigations are usually enterprise matters, so the centre of gravity is server-side and tenant-side rather than on any one device. Endpoint work is targeted at custodians the enterprise records already point to.
Tenant and identity
The Microsoft 365 unified audit log records mail, file, sharing, administrative and policy operations across the tenant, and it is normally the backbone of an investigation of this kind — subject to a retention window that depends on licence and configuration. Entra ID sign-in logs record authentication with application, device, address and conditional-access outcome, and administrative audit records show changes to roles, policies and mailbox permissions — including changes made during the investigation.
Endpoint and security stack
EDR telemetry and process creation events record execution with command lines and parent processes; endpoint protection logs record detections and, importantly, exclusions somebody configured; and logon events supply the authentication half on the device side. SRUM records per-application network volume in hourly buckets, which is frequently the only local measure of how much data left a machine.
Movement of data
Sync client records, browser downloads and removable device history answer the exfiltration limb where one exists. Data loss prevention and mail gateway records add the enterprise view, and where the investigation concerns an intrusion rather than an insider, the same sources support the incident reconstruction described on the server forensics page.
What this evidence cannot establish
- Whether the conduct broke a rule or a law. An examiner establishes what systems and accounts did. Whether that was a policy violation, a securities offence, an export breach or nothing at all is the assessment counsel and the regulator make, and an expert who states it has left the discipline for the one place a tribunal is watching.
- That the collection was complete. Collections proceed from a custodian list and a systems inventory, both of which are human products assembled under time pressure. A shadow system nobody mentioned, an account outside the tenant, a personal device — the examination reports what was collected and from where, and completeness is a claim about the inventory rather than about the evidence.
- That privilege was not breached. What can be shown is that a defined protocol was applied, that the segregated set was isolated, and that the access log records who could reach what. Absolute assurance is not available, and a report offering it is claiming something the logs do not carry.
- Who was behind a shared or service account. Administrative and service credentials are used by several people and by automation, and elevated access is precisely where investigations concentrate. Attribution needs corroboration from outside the systems, and often none exists.
- What deleted material contained, or why it went. A deletion outside the ordinary retention schedule is a finding worth stating precisely and dating carefully. What was in the deleted material, and whether anyone intended to obstruct anything, are not things the record establishes.
Where the dispute is about the discovery process itself — ESI protocol negotiation, search-term validation, technology-assisted review — that is covered at ediscoveryexpertwitness.com. Where a court appoints a neutral to supervise the examination, technicalspecialmaster.com sets out that role, and where an incident has moved into breach negotiation, databreachmediator.com covers it.
The expert’s role and the deliverable
- Write the preservation scope down, then issue it. A litigation hold naming custodians, systems and date ranges, with automatic deletion suspended and the reasoning recorded. The preservation deadline calculator sets out how fast the common sources age out, and the volatile ones are captured the same day rather than staged.
- Establish the privilege protocol before the first collection. Who reviews, in what order, behind which wall, with what filtering, and how access is logged. Designed after collection has begun, a protocol is a remediation; designed before, it is a defence.
- Collect forensically even when nobody has sued. Hashes at acquisition and verification, custody records, exports whose queries and date ranges are recorded so the collection can be repeated. The cost difference against an informal copy is small; the difference in what the material can later be used for is not.
- Keep the analysis reproducible and the notes disciplined. Every search, filter and tool version recorded, so a finding can be re-derived by someone who was not in the room. Interim material in an investigation is frequently produced later, and it should read as work that expected to be.
- Report to the audience present, at the standard of the audience to come. A board briefing and a regulator submission look different and should rest on the same examination. The rule that makes that possible is simple: nothing in the briefing that the underlying record does not support.
- Testify, where the matter goes that way. A consulting examination becomes a Rule 26(a)(2)(B) disclosure when a testifying role is taken up, and the transition is far easier where the work was documented as though it would be. How that report is scoped and defended is set out on the expert witness testimony page.
Where the pressure falls here
Some of this work never reaches a courtroom, and the standards applied to it are no softer for that. A regulator asks how the conclusion was reached; a board committee asks what it rests on; and if a civil action follows, Rule 702 as amended on December 1, 2023 asks whether the opinion reflects a reliable application of the method to the facts of the case. The failure modes are shared.
- Scope limits that were never disclosed. An investigation that examined four custodians out of a population of forty reached a defensible conclusion about four custodians. Where the report does not say so, the omission is what the cross-examination is about.
- Privilege screening that cannot be evidenced. A protocol nobody logged is indistinguishable, months later, from a protocol nobody followed. The access record is what converts an assertion about the wall into a fact about it.
- Preservation gaps discovered by the other side. Retention settings, hold dates and deletion events are all establishable facts. Establishing them yourself, early, is a different posture from having them established for you at a sanctions hearing.
- A board deck offered as an expert opinion. Investigation summaries are written to be read quickly, with confident headline findings and the qualifications compressed out. Repurposed as expert evidence, the compression is the problem, and the underlying work usually deserved better.
- Legal conclusions in a technical report. “Unauthorised”, “misappropriated”, “fraudulent” and “in violation of” are characterisations, not findings. Removing them costs nothing and removes the easiest available attack.
| RECORD | WHAT IT ESTABLISHES | WHAT IT DOES NOT ESTABLISH |
|---|---|---|
| Microsoft 365 unified audit log | Mail, file, sharing and administrative operations across the tenant, with actor, target and time | Content of the items acted on, and anything outside the retention window the licence and configuration set |
| Entra ID sign-in logs | Authentication with application, device, address and conditional-access outcome | The person behind the credential, or the physical location of the session |
| Administrative and policy change records | Changes to roles, permissions, retention and mailbox delegation — including changes made after the investigation began | Why a change was made, or whether it was authorised by anyone with the standing to authorise it |
| EDR telemetry and process creation events | Execution with command lines and parent process, across covered endpoints | That an endpoint was covered at all on the date in question, and retention is frequently measured in days |
| Endpoint protection logs | Detections, quarantines, and the exclusions somebody configured — which are often the more interesting entry | That nothing malicious ran. Detection depends on signatures, coverage and configuration |
| Retention and hold configuration | What the deletion schedule was, when a hold was applied, and which custodians and systems it reached | What was lost before the hold. Absence within a rolled window is not evidence of deletion |
| Privilege review access logs | That a defined protocol was applied and which reviewers could reach the segregated set | That no privileged material was ever seen by anyone outside the wall |
Questions counsel ask
How wide should the preservation scope be at the start?
What does the forensic examiner do about privilege?
Employees are being interviewed. Does that affect the forensic work?
The investigation was for the board. Now a regulator wants the findings. Is that a problem?
Can you examine an employee's personal phone or laptop?
What happens if data was already lost before anyone acted?
Related reading
- Cloud forensics
Tenant audit logs, retention windows, API-only collection, and what a cloud provider does and does not keep on your behalf.
- Server forensics
Domain controllers, application and access logs, and the reconstruction of activity across systems rather than on one device.
- Employment and departing employees
Where an internal investigation concerns one custodian's access — account-versus-person attribution, and authorisation scope.
- How to hire and vet a forensic expert
Consulting versus testifying versus court-appointed, what to demand before retention, conflicts, timing, and cost.
Endpoint telemetry rolls off in days, tenant audit retention was set years ago by someone who has left, and the preservation decision is judged later on what was written down at the time. Send the matter, the regulator or forum if there is one, the custodian population, and where the systems sit — a conflicts check and a scoping call follow.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
Attorney advertising / expert services. This page describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Prior results do not guarantee a similar outcome.