Posted on: February 23, 2017in Blog
Corporate Internal Investigations Best Practices
An estimated 93% of all data created by corporations is in the electronic format. Subsequently, the number of sanctions levied against parties who improperly handle electronic evidence continues to increase.
Here are 11 best practices that should be followed when planning and conducting an internal investigation.
Internal Investigations Best Practices
1. Identify trigger events
Identify your specific trigger events. This would be anything that would cause you to take action from a legal, compliance or investigative standpoint. Document these triggers and make the records available to stakeholders.
2. Identify external contacts
Identify your key external contacts and document their information. Ideally, you will have contracts in place ahead of time to avoid negotiating a statement of work for a time sensitive issue.
3. Identify internal contacts & roles
Identify your key internal contacts and document their roles. Document their individual roles and responsibilities within the investigation process. Once you have identified your internal team, get them in a room together to begin building relationships and agreed upon protocols.
4. Have an investigation plan
Have a plan or policy in place on what to do when a trigger event occurs and how to defensibly handle the investigation.
5. Document entire your process
Documentation is your sword in negotiating a reasonable scope of discovery and your shield in showing that what you included or excluded in preservation and collection was reasonable.
6. Document your chain of custody
Document your chain of custody. This document should provide details regarding the collection, transportation, storage and general handling of electronic evidence.
7. Avoid evidence spoliation
Treat the suspect employee’s computer like a crime scene. Every time an untrained individual accesses – or attempts to access – the data on the devices, they run the risk of unintentional destruction of data, or at best, significant changes to the data that cannot be undone.
8. Collaborate with external expertise
Collaborate with outside counsel and/or a forensic examiner to dive deeper into the data. This will arm you with valuable information about the case.
9. Preserve the entire workstation
Your first step should always be to preserve the suspect’s workstation and immediately call a forensics expert. Have the full internal team on this call, and be prepared to discuss the facts of the case/background, end goals, and timeline of events.
10. Use forensic expertise & tools
Remember: trained forensic examiners with proper tools can recover deleted information. This enables them to piece together a story that traditional discovery methods cannot.
11. Be prepared to testify
Be prepared to testify if you are handling the electronic evidence. You must be able to defend the accuracy of the evidence collected, and testify to the actual collection process. If this is an internal individual, then be prepared for questions surrounding bias and expertise.
Download the PDF version of these best practices - which includes a reference sheet for you to create your own lockstep protocol for handling internal investigations.
- 4 Key Internal Roles Involved with Conducting Corporate Investigations
- Intellectual Property Theft: How to Ensure a Defensible Investigation
- Legal Hold Triggers: When Should You Document Your Reasonable Expectation of Litigation?
- Forensic Investigations Unlock Key Digital Evidence
D4 Weekly eDiscovery Outlook
Power your eDiscovery intellect with our weekly newsletter.
Posted November 16, 2017
5 Workflow Tips for Conducting a Foreign Language Review
Posted November 10, 2017
What You Need to Know About Managed Review and the eDiscovery Process
Posted November 02, 2017
7 Steps to Help You Defensibly Migrate eDiscovery Data
Posted October 27, 2017
CLE Webinar with Lewis Brisbois: How to Do Social Media Collection and Presentation Right
Posted October 26, 2017
Despite Clawback, Defendant’s Reckless Abandon of Rule 502 Bites Back
Posted October 20, 2017
How to Use the eDiscovery PST Export Tool in Office 365 E3
Posted October 12, 2017
Recent eDiscovery Cases for Mobile Phones and Social Media
Posted October 05, 2017
Raising Objections to the Format of ESI Productions: Do it Early and Do it Clearly
Posted September 27, 2017
5 Reasons eDiscovery Alternative Fee Models Make Sense for You
Posted September 22, 2017
Why it's Crucial to Have a Corporate Mobile Device Policy