The short answer
The first thirty days of a corporate fraud investigation decide what can be recovered and what will be admissible. The sequence is preservation and containment before inquiry, a defined privilege structure, an established perimeter of what happened and over what period, and only then interviews — with confrontation of the suspect deliberately last.
How these start
Corporate fraud rarely announces itself. It arrives as a discrepancy someone could not reconcile, a supplier querying an invoice nobody recognises, a bank asking about a payment, an auditor's note, a resignation that came at a strange moment — or, most often, because somebody said something. The ACFE's Report to the Nations has consistently found tips to be the leading detection method, ahead of internal audit and automated controls, which is a finding about organisations rather than about fraud: the control that works best is a person deciding to speak.
Whatever the trigger, the organisation is now in a position it is not practised at. There is a suspicion, an incomplete picture, a named individual or two in people's minds, and a strong institutional instinct to resolve it quickly and quietly by asking the person about it. That instinct is the single most expensive reflex in this entire process, and the first job of anyone competent is to interrupt it.
The reason is simple. At the moment a suspicion surfaces, the evidence still exists, the money may still be reachable, and the subject does not know. Each of those three conditions is destroyed by a premature conversation, and none of them can be restored. What follows is what the first month should look like instead. This piece is about the domestic corporate engagement; where value or counterparties have crossed a border the sequencing changes materially, and that is covered in cross-border fraud investigation.
Days 0 to 3: preserve, contain, and decide who knows
Nothing in the first seventy-two hours is about finding out who did it. It is about making sure that the answer remains findable and that the organisation has not damaged its own position.
Preservation comes first. Issue a litigation hold suspending routine deletion, and have IT preserve mailboxes, file shares, system and access logs, and any relevant device images — quietly, through a named individual, without a general announcement. Federal Rule of Civil Procedure 37(e) provides for sanctions where electronically stored information that should have been preserved is lost because reasonable steps were not taken, and where a party acted with intent to deprive another of the information the available sanctions are severe. Preservation failures also read badly to a regulator and an insurer, entirely apart from the litigation risk.
Second, decide the privilege structure before the work starts. Where a matter may result in litigation, regulatory engagement or an insurance claim — which is most of them — the investigation is normally directed by counsel, internal or external, with investigators and forensic accountants engaged through counsel. This has to be set up at the outset, because it cannot be applied retrospectively to work already done another way.
Third, contain without confronting. Access can be restricted, approval thresholds lowered, and payment runs subjected to second review, all of which can be framed as ordinary controls work. Suspension or restriction aimed visibly at one individual tells them the investigation exists. And the containment decision has a genuine tension in it: every day the suspected conduct continues is further loss, but acting visibly too early forfeits the evidence. That is a judgment, and it belongs to a small defined group.
Fourth, two clocks nobody remembers. Fidelity bond and commercial crime policies carry notice provisions with real deadlines, and late notice is a common reason recovery under the policy fails. And where the organisation is a regulated financial institution, suspicious activity reporting obligations run on their own statutory timetable regardless of how the internal investigation is progressing.

Days 3 to 10: establish the perimeter
The second phase answers four questions, and deliberately not the question everyone wants answered.
What actually happened, mechanically — which transactions, which accounts, which approvals, which systems. Over what period, which almost always turns out to be longer than the trigger event suggested; the ACFE's studies repeatedly find schemes running for a substantial period before detection, and the first identified transaction is rarely the first transaction. How much, expressed as a defensible range rather than a number, because an early precise figure will be wrong and will be quoted back later. And who had the access and authority to do it, established from system entitlements and approval matrices rather than from assumption.
That last point is where discipline matters most. The temptation is to start from the individual people already suspect and look for evidence against them, which is both analytically backwards and, if the suspicion is wrong, seriously damaging to a person who has done nothing. Starting from the mechanism and asking who could have executed it produces a defined population — sometimes one person, often several, occasionally nobody inside the organisation at all. Payment-diversion fraud in particular presents exactly like an internal fraud in its early stages: the FBI's Internet Crime Complaint Center recorded roughly $2.77 billion in business email compromise losses in 2024, and a diverted supplier payment looks, from the ledger, very much like someone inside redirecting funds.
This phase also produces the first honest scoping decision. A defined perimeter is what allows the engagement to be scoped and priced properly instead of running open-endedly, and it is the point at which a competent adviser should tell a client if the matter is smaller than feared.
Days 10 to 20: evidence that will survive being challenged
By now the investigation is producing findings, and the standard applied to them determines whether they are usable in the proceedings that may follow — employment, civil recovery, insurance, regulatory, or criminal referral. Work built to a lower standard has to be redone at exactly the moment there is no time to redo it.
In practice that means forensic imaging rather than copying, with documented chain of custody from collection onward; authentication of documents rather than acceptance of what was produced; reconciliation of every asserted figure to a source record; and a clear separation, maintained in the writing, between what has been established, what is inferred, and what a witness has alleged.
Interviews belong in this phase, and their sequence is not a matter of style. Peripheral witnesses first — the people who processed, approved or noticed things — because they establish the factual frame and because interviewing them later, after the subject knows, produces worse evidence. The subject is interviewed last, once the record is well enough established that answers can be tested against it rather than taken on trust.
Employee interviews in a corporate investigation carry a specific obligation. Under Upjohn Co. v. United States the corporation's attorney-client privilege can cover counsel's communications with employees, but the privilege belongs to the company and not to the employee — so the employee must be told, at the outset, that counsel represents the company rather than them, and that the company may choose to waive privilege and disclose what they say. That is the Upjohn warning, and giving it properly protects both the employee's understanding and the company's ability to rely on the privilege later. The employment-side version of this discipline, where the conduct is workplace rather than financial, is set out in internal and workplace investigations.
Days 20 to 30: the decisions that cannot wait
The final phase of the first month is where the investigation stops being an inquiry and starts producing consequences. Four decisions typically arrive together, and they interact.
Recovery. If money has moved, tracing it competes directly with the subject's ability to move it further, which is why this work belongs at the start of the month rather than the end wherever the loss is significant. Domestically that means property records, entity formations and transfers made since the conduct began, as set out in asset tracing for judgment enforcement; where value has left the jurisdiction the remedies and their sequencing are covered in cross-border fraud and the legal remedies that recover the money.
Reporting. Regulated institutions have suspicious activity reporting obligations on a statutory clock. Public companies have auditor and audit committee obligations. The insurer has been notified already if the first phase was run properly. And there is a discretionary decision about law enforcement referral, which is genuinely a decision: referral brings investigative powers the company does not have, and it also transfers control of timing, disclosure and outcome away from the company.
People. Employment action has its own legal framework and its own evidentiary standard, which is not the criminal one. It should follow the investigation rather than pre-empt it, and it should be documented separately from it. The outcome most likely to cause regret is the quiet negotiated resignation with no findings recorded — it ends the immediate discomfort, forfeits the recovery, complicates the insurance claim, and sends an unvetted individual to the next employer with a clean reference.
Remediation. The control that failed is still failing. The DOJ's Evaluation of Corporate Compliance Programs asks specifically whether a company performed a root cause analysis of misconduct and what remedial measures followed, including discipline applied consistently. A programme that identifies an individual and changes nothing structural has not finished the work — and where the answer to "how was this possible" is uncomfortable, that answer is the most valuable output of the whole exercise.
The mistakes that cost the most
These recur across matters of every size, and every one of them is committed with good intentions.
- Confronting the suspect early. It feels decisive and direct. It tells the subject to delete, to move money, to align accounts with colleagues, and to obtain advice — and it converts a recoverable situation into a contested one.
- Letting IT investigate alone. IT can preserve and image, and should. IT should not be conducting the investigation: the work needs an evidentiary standard, an interview method and a privilege structure that a systems team is not resourced to provide, and an internal investigator may end up as a witness.
- No litigation hold. Routine deletion policies keep running while everyone assumes somebody has stopped them. Under Rule 37(e) the consequences of losing electronically stored information that should have been preserved are borne by the company, not by whoever forgot.
- Telling too many people. The circle expands from the audit committee to the CFO to a manager to a colleague, and the subject learns within days. A small written distribution list, agreed at the start, is a control in itself.
- Announcing a number too early. An early precise loss figure will be wrong, and it will be quoted back by the insurer, the auditor and opposing counsel. Ranges, revised as the perimeter firms up.
- The quiet exit. Accepting a resignation and closing the file forfeits recovery, weakens the insurance claim, and passes the problem to the next employer.
- Treating the individual as the whole answer. The person is the proximate cause; the control that permitted it is the reason it happened and the reason it can happen again.
How the engagement is scoped and what it costs
Fraud investigations are the one discipline in this field that genuinely resists fixed-fee pricing at the outset, because the perimeter is unknown on day one — and any provider offering a firm total before the perimeter exists is guessing.
The workable structure is phased. A short fixed-fee triage in the first days establishes whether there is something real, secures preservation, and produces a scoping recommendation. A defined-fee scoping phase establishes the perimeter — mechanism, period, magnitude range, population with access. Only then can the full investigation be estimated with any honesty, and it should be re-estimated if the perimeter moves.
The cost drivers are the volume of data requiring forensic review, the number of interviews, the number of entities and jurisdictions, and whether the work must meet an evidentiary standard for proceedings rather than an internal one. The wider map of which discipline a given situation actually calls for is set out in corporate investigation services, and the offence categories themselves in white-collar crime investigations, explained.
Key takeaways
- Nothing in the first seventy-two hours is about identifying the perpetrator. It is preservation, a privilege structure set up before work begins, containment that does not signal, and the insurance and reporting clocks nobody remembers.
- Start from the mechanism, not the suspect. Establishing what happened and who had the access and authority to do it produces a defined population — and protects anyone wrongly suspected.
- Interview peripheral witnesses first and the subject last, and give employees the Upjohn warning: counsel acts for the company, the privilege belongs to the company, and the company may waive it.
- Litigation holds are forgotten while routine deletion keeps running. Rule 37(e) places the consequences of unpreserved electronically stored information on the company.
- The quiet negotiated resignation is the most expensive outcome available: it forfeits recovery, weakens the insurance claim, leaves the failed control in place, and passes an unvetted individual to the next employer.
Frequently asked
10 questionsWhat are the first steps in a corporate fraud investigation?
Preserve, structure, contain, and check the clocks — in that order, and before any inquiry into who is responsible. Issue a litigation hold and have IT quietly preserve mailboxes, file shares, logs and device images. Engage investigators through counsel so privilege attaches from the outset. Tighten controls in ways that read as ordinary rather than targeted. And check the fidelity bond or crime policy notice deadline and any regulatory reporting obligation, both of which run on their own timetable.
Should we confront the employee we suspect?
Not early, and not before the record is established. Confrontation tells the subject to delete material, move funds, align accounts with colleagues and obtain advice, and it converts a recoverable situation into a contested one. The subject is interviewed last, once there is enough independent evidence that their answers can be tested rather than simply accepted or disbelieved.
What is an Upjohn warning and when is it required?
It is the notice given to an employee at the start of an interview conducted by or for company counsel: that counsel represents the company and not the employee, that the privilege over the conversation belongs to the company, and that the company may choose to waive it and disclose what is said. It follows from Upjohn Co. v. United States, which established that corporate attorney-client privilege can cover counsel's communications with employees. Giving it properly protects both the employee's understanding and the company's ability to rely on the privilege later.
Why does a litigation hold matter so much?
Because routine deletion policies keep running unless someone stops them, and the loss falls on the company. Federal Rule of Civil Procedure 37(e) provides for sanctions where electronically stored information that should have been preserved is lost because reasonable steps were not taken, with severe measures available where a party acted with intent to deprive another of it. Preservation failures also weigh badly with regulators and insurers independently of any litigation.
Should IT run the investigation?
IT should preserve and image, and that work is essential. It should not run the investigation. The matter needs an evidentiary standard with documented chain of custody, an interview method, and a privilege structure that a systems team is not resourced to provide — and an employee who conducts the investigation may become a witness in the proceedings that follow, which is a poor position for both them and the company.
When should we report to law enforcement?
It is a genuine decision rather than an automatic step, except where a statutory obligation applies — regulated financial institutions have suspicious activity reporting duties on their own clock, and public companies have auditor and audit committee obligations. Referral brings investigative powers the company does not have. It also transfers control of timing, disclosure and outcome away from the company, which can affect recovery and can complicate a parallel civil claim. The decision is usually best taken once the perimeter is established.
How is this different from an internal or workplace investigation?
The overlap is real but the centre of gravity differs. Workplace investigations concern conduct — harassment, discrimination, policy breach — and are built around employment law, procedural fairness and an internal standard of proof. A fraud investigation concerns financial loss and is built around tracing money, evidence that must survive challenge in civil or criminal proceedings, insurance recovery, and remediation of the control that failed. Many matters begin as one and become the other.
How long does a corporate fraud investigation take?
The first thirty days establish preservation, perimeter and the immediate decisions. A contained matter with a defined population and a manageable data volume may conclude within that window. Matters involving multiple entities, large volumes of electronic data, several jurisdictions, or evidence that must meet a standard for proceedings routinely run several months. The honest answer on day one is that the duration cannot be estimated until the perimeter is established, which is itself a defined and short phase.
What does a corporate fraud investigation cost?
It is one of the few engagements that genuinely resists a fixed fee at the outset, because the perimeter is unknown on day one — a firm total quoted before scoping is a guess. The workable structure is phased: a short fixed-fee triage that secures preservation and recommends scope, a defined-fee scoping phase that establishes mechanism, period, magnitude range and the population with access, and only then an estimate for the full investigation. Drivers are data volume, interview count, entities and jurisdictions, and the evidentiary standard required.
What should happen after the investigation concludes?
Four things, and the last is the one most often skipped. Pursue recovery through civil claim, insurance and any restitution route. Complete reporting obligations. Take employment action on its own standard and documented separately from the investigation. And remediate the control that failed — the DOJ's compliance-program guidance asks specifically whether a company performed a root cause analysis and what remedial measures followed, because identifying an individual while leaving the structural gap in place means the same thing can happen again.
Sources & further reading
- 01ACFE — Report to the NationsThe global occupational-fraud study finds tips to be the leading detection method, ahead of internal audit and automated controls, and finds schemes running for a substantial period before detection — which is why the first identified transaction is rarely the first transaction.
- 02Upjohn Co. v. United States, 449 U.S. 383 (1981)Established that a corporation's attorney-client privilege can extend to counsel's communications with employees. Because the privilege belongs to the company rather than the employee, the interviewee must be told so at the outset — the Upjohn warning.
- 03Federal Rule of Civil Procedure 37(e)Provides for measures where electronically stored information that should have been preserved in anticipation of litigation is lost because reasonable steps were not taken, with the most severe sanctions available where a party acted with intent to deprive another of the information.
- 04U.S. Department of Justice, Criminal Division — Evaluation of Corporate Compliance ProgramsAsks whether a company conducted a root cause analysis of the misconduct, what remedial measures followed, and whether discipline was applied consistently — the standard against which the remediation phase is assessed.
- 05FinCEN — suspicious activity reporting requirements, 31 CFR Chapter XRegulated financial institutions carry SAR filing obligations that run on a statutory timetable independent of the progress of any internal investigation, which is why the reporting clock belongs in the first seventy-two hours rather than the final week.
- 06FBI Internet Crime Complaint Center (IC3), Internet Crime Report 2024Approximately $2.77 billion in business email compromise losses in 2024 — the reason a diverted supplier payment, which from the ledger resembles an internal fraud, has to be excluded before an internal population is defined.

