Posted on: February 23, 2017in Blog
Corporate Internal Investigations Best Practices
An estimated 93% of all data created by corporations is in the electronic format. Subsequently, the number of sanctions levied against parties who improperly handle electronic evidence continues to increase.
Here are 11 best practices that should be followed when planning and conducting an internal investigation.
Internal Investigations Best Practices
1. Identify trigger events
Identify your specific trigger events. This would be anything that would cause you to take action from a legal, compliance or investigative standpoint. Document these triggers and make the records available to stakeholders.
2. Identify external contacts
Identify your key external contacts and document their information. Ideally, you will have contracts in place ahead of time to avoid negotiating a statement of work for a time sensitive issue.
3. Identify internal contacts & roles
Identify your key internal contacts and document their roles. Document their individual roles and responsibilities within the investigation process. Once you have identified your internal team, get them in a room together to begin building relationships and agreed upon protocols.
4. Have an investigation plan
Have a plan or policy in place on what to do when a trigger event occurs and how to defensibly handle the investigation.
5. Document entire your process
Documentation is your sword in negotiating a reasonable scope of discovery and your shield in showing that what you included or excluded in preservation and collection was reasonable.
6. Document your chain of custody
Document your chain of custody. This document should provide details regarding the collection, transportation, storage and general handling of electronic evidence.
7. Avoid evidence spoliation
Treat the suspect employee’s computer like a crime scene. Every time an untrained individual accesses – or attempts to access – the data on the devices, they run the risk of unintentional destruction of data, or at best, significant changes to the data that cannot be undone.
8. Collaborate with external expertise
Collaborate with outside counsel and/or a forensic examiner to dive deeper into the data. This will arm you with valuable information about the case.
9. Preserve the entire workstation
Your first step should always be to preserve the suspect’s workstation and immediately call a forensics expert. Have the full internal team on this call, and be prepared to discuss the facts of the case/background, end goals, and timeline of events.
10. Use forensic expertise & tools
Remember: trained forensic examiners with proper tools can recover deleted information. This enables them to piece together a story that traditional discovery methods cannot.
11. Be prepared to testify
Be prepared to testify if you are handling the electronic evidence. You must be able to defend the accuracy of the evidence collected, and testify to the actual collection process. If this is an internal individual, then be prepared for questions surrounding bias and expertise.
Download the PDF version of these best practices - which includes a reference sheet for you to create your own lockstep protocol for handling internal investigations.
- 4 Key Internal Roles Involved with Conducting Corporate Investigations
- Intellectual Property Theft: How to Ensure a Defensible Investigation
- Legal Hold Triggers: When Should You Document Your Reasonable Expectation of Litigation?
- Forensic Investigations Unlock Key Digital Evidence
D4 Weekly eDiscovery Outlook
Power your eDiscovery intellect with our weekly newsletter.
Posted June 21, 2017
Strategic Ways to Reduce the Cost of eDiscovery
Posted June 15, 2017
Shanghai OSAC Quarterly Meeting
Posted June 15, 2017
5 Ways to Reduce eDiscovery Costs Before and During Litigation
Posted June 07, 2017
Defensible Deletion Strategy: Getting Rid of Your Unnecessary Data
Posted May 31, 2017
How Does the EU-US Privacy Shield Affect Cross-Border Discovery?
Posted May 24, 2017
Unique eDiscovery Challenges with Mobile Device Data and How to Solve Them
Posted May 17, 2017
How to Comply with 21 CFR and HIPAA Data Retention Requirements
Posted May 11, 2017
4 Key Advantages of Conducting Remote Depositions
Posted May 03, 2017
eDiscovery in International Dispute Resolution: What Experts Want You to Know
Posted April 27, 2017
China Expands Data Transfer Requirements for its Cybersecurity Law