Board-Led Corporate Internal Investigations in India: Evidence, Independence, Interviews, Reporting & Remediation Guide 2026
A corporate investigation protocol for boards, promoters, audit committees, legal teams and senior management dealing with fraud, misconduct, conflicts, data leakage, vendor collusion or control failure.
A serious internal investigation is a governance process, not an informal fact-finding conversation. Once allegations concern senior employees, procurement, financial leakage, data misuse, conflicts of interest or management override, the company needs a documented investigation architecture that can withstand scrutiny from the board, auditors, regulators, employees, counterparties or a court.
The quality of an investigation often depends on decisions made in the first 48 hours: who controls the mandate, what evidence is preserved, whether relevant persons are alerted prematurely, whether access is restricted, and whether the investigation team is sufficiently independent from the events under review.
1. When should the board commission an internal investigation?
Escalation is usually justified where the allegation is material, repeated, involves senior management, may affect financial statements or assets, presents retaliation risk, involves sensitive data, may trigger regulatory reporting, or indicates that an existing control environment has failed.
Examples include suspected vendor collusion, undisclosed related-party transactions, manipulation of procurement, employee data theft, false claims, diversion of customers, accounting irregularities, conflicts of interest, whistleblower complaints, unexplained inventory or cash loss, falsified BGV records, and systematic override of approval controls.
For the broader control framework, see Corporate Risk Mitigation in India and Internal Investigation of Employee Misconduct in India.
2. Terms of reference: the investigation charter
A written mandate should define:
- the allegations and relevant period;
- entities, functions, locations and systems in scope;
- who commissioned the investigation;
- who receives updates and the final report;
- authority to obtain records and interview personnel;
- whether external forensic, accounting or cyber specialists may be engaged;
- confidentiality and information-sharing rules;
- process for escalation of new allegations;
- limitations, including unavailable data; and
- the standard used for findings.
Without a clear charter, investigations drift, duplicate work and create disputes about authority or fairness.
3. Investigator independence and conflicts
The investigation team should be independent from the persons and processes under review. If the allegation concerns the CFO, a finance-controlled investigation may not be credible. If it concerns procurement leadership, procurement should not control evidence collection. Where senior management is implicated, the reporting line may need to move to the board, Audit Committee or another authorised independent body.
Potential conflicts should be recorded at the outset. The investigation should also avoid giving decision-making authority to a person who may later need to defend their own conduct.
4. Evidence preservation and legal hold
A preservation notice should identify relevant custodians, systems and document types. Depending on the allegation, the company may need to preserve email, Teams/Slack-type messages, ERP records, CRM exports, access logs, audit trails, bank files, procurement documents, vendor masters, expense claims, HR records, CCTV within retention limits and company-owned devices.
Preservation should occur before routine deletion cycles overwrite data. CERT-In’s 2022 Directions require body corporates and specified entities to enable ICT-system logs and maintain them securely for a rolling 180-day period within India, making log management directly relevant to investigation readiness.
Where digital personal data is involved, collection and review should also be assessed against the Digital Personal Data Protection Act, 2023 and the staged commencement of the DPDP Rules, 2025. An investigation does not justify indiscriminate collection unrelated to the allegation.
5. Evidence map
| Allegation | Evidence to test | Corroboration |
|---|---|---|
| Vendor collusion | Vendor master, POs, pricing, bank details, communications | KYC, corporate records, employee conflicts |
| Data leakage | Access logs, downloads, exports, email forwarding | Role access, resignation timeline, competitor contact |
| Expense fraud | Claims, receipts, approvals, card records | Travel data, vendor confirmation |
| Management override | ERP and bank logs, exception approvals | Policy thresholds, approval matrix |
6. Interview sequencing
Interviews should usually follow sufficient document review to make questioning specific. A useful sequence often begins with process owners and neutral witnesses, moves to persons with direct knowledge, and leaves key subjects until the investigation team understands the documentary record.
Interview notes should identify attendees, date, purpose and material answers. Leading or accusatory questioning should be avoided where the facts remain open. Where employment consequences may follow, the company should align the investigation process with applicable service rules, contracts, standing orders, disciplinary procedures and principles of fairness.
7. Confidentiality and legal privilege
Investigation information should be distributed on a need-to-know basis. Over-circulation can compromise witnesses, damage reputations and create avoidable disclosure risk. Where legal counsel is engaged, the company should define the legal purpose of the engagement and obtain case-specific advice on confidentiality and professional-communication protections rather than assuming every internal document is privileged merely because a lawyer receives it.
8. Interim controls while the investigation is open
Companies often need to contain risk before reaching a final finding. Interim measures can include enhanced approval requirements, temporary restriction of system access, dual approval for payments, suspension of vendor onboarding, independent review of bank-detail changes, preservation of company devices, or temporary reassignment of duties.
Interim action should be proportionate and should not be presented as a final finding of guilt.
9. Findings: use a disciplined structure
For each allegation, the report should state:
- the allegation;
- the evidence reviewed;
- material facts established;
- evidence supporting and contradicting the allegation;
- the conclusion and level of confidence;
- financial or operational exposure;
- control failures; and
- recommended remediation.
Labels such as “substantiated,” “partially substantiated,” “not substantiated,” or “inconclusive” should be defined and applied consistently.
10. Board reporting
A board-level report should not bury the decision points. The executive section should identify material exposure, persons/functions involved, whether misconduct appears isolated or systemic, immediate containment actions, financial quantification where possible, reporting considerations, employment/contractual steps and remediation deadlines.
The detailed evidentiary schedules can sit behind the executive report. This allows directors to understand the risk without losing the audit trail.
11. Investigation governance matrix
| Stage | Primary owner | Key control |
|---|---|---|
| Commissioning | Board / authorised management | Written terms of reference |
| Preservation | Legal / IT / forensic | Chain of custody and retention hold |
| Testing | Investigation team | Documented methodology |
| Interviews | Investigation team | Consistent notes and corroboration |
| Conclusion | Independent reviewer / commissioner | Evidence-based finding |
| Remediation | Business owners | Named owner, deadline and validation |
12. Remediation after the report
An investigation is incomplete if the same weakness remains open. Remediation may require policy change, access redesign, vendor re-KYC, approval-matrix changes, disciplinary proceedings, contract termination, recovery action, enhanced monitoring, whistleblower improvements, board oversight or referral to specialist counsel for regulatory or criminal-law assessment.
Root-cause remediation is more valuable than merely identifying a person. If the system made the conduct easy, the system must change.
13. Frequently asked questions
Should HR always lead an internal investigation?
No. The lead should depend on the allegation and conflict profile. Board-level fraud, procurement or data matters may need independent legal, forensic or audit oversight.
Can company devices be reviewed?
Potentially, subject to ownership, policy, lawful access, relevance, privacy and case-specific requirements.
Should the subject receive the full evidence file?
The applicable employment and disciplinary process should determine what disclosure is required. Internal investigation and formal disciplinary inquiry are not always the same process.
When should police or regulators be informed?
That requires case-specific legal analysis based on the nature of the conduct, applicable reporting duties, evidence and strategic considerations.
What is the most common investigation failure?
Starting interviews before preserving and understanding the documentary record.
Authoritative references
- Companies Act, 2013 — India Code
- Digital Personal Data Protection Act, 2023 — India Code
- CERT-In Directions, 2022
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.