A practical guide for conducting and supervising internal investigations in India
By Tanya Ganguli
When a serious allegation surfaces (whether through a whistleblower complaint, an internal audit finding, or a regulatory query), the Board of Directors and/or Audit Committee face a set of decisions that must be made quickly and correctly. Who investigates? Who oversees the investigation? What’s the mandate? How do we scope the allegation? How is privilege protected? What must be disclosed, and to whom?
This guide is designed as a reference point for such decisions, while focusing on the Indian legal and regulatory framework governing internal investigations, and sets out a practical framework for conducting effective investigations. No two investigations are alike, so there is no straitjacket formula. However, this guide has been prepared with reference to best practices in this space, most of which are consistent with international norms, while flagging the aspects of Indian law and practice, such as privilege, evidence handling, and disclosure timelines, that call for distinct treatment.
It does not replace legal advice (the facts of each case always matter), but it sets out the steps that experienced practitioners consider at each stage of a corporate investigation.
1. Before the allegation surfaces
- Maintain a whistleblower reporting channel that allows for anonymous reporting and includes effective safeguards against retaliation. The channel should be accessible to all employees and third parties, with a documented process for receiving, recording, and routing complaints.
- Implement and review annually the core policies governing ethical conduct, anti-bribery and corruption, conflicts of interest, and internal financial controls. Document the outcome of each review and track gaps to closure.
- Identify key sources of electronic evidence within the organisation’s IT systems (email servers, financial systems, collaboration tools, CCTV, access logs) and put in place data preservation protocols that can be activated within hours of a complaint being received.
- Conduct an annual (or as frequently needed) tabletop exercise simulating an investigation scenario, involving the Audit Committee Chair, General Counsel, Chief Compliance Officer, CISO, CFO, Head of HR and/or any other stakeholders deemed necessary. The exercise should test decision-making under time pressure and identify gaps in readiness.
2. First 48 hours of receiving a complaint
- Record the complaint in writing immediately (if not done already): the source (named or anonymous), date and time of receipt, the nature of the allegations, persons named or implicated, and any supporting material provided.
- If the complainant is identifiable, confirm in writing that they are protected from retaliation. Communicate this protection to the relevant line managers or HR personnel without disclosing the substance of the complaint.
- Conduct a preliminary credibility assessment: verify whether the persons, departments, transactions, or documents named in the complaint actually exist. Do not probe the merits of the allegations at this stage. Do not dismiss a complaint solely because it is anonymous.
- Contact external legal counsel promptly. Engage forensic accountants or technology experts where the complaint involves financial irregularities or digital evidence. If organisational procurement policy requires it, initiate the vendor selection process without delay.
- Exclude from all investigation-related decisions and document handling: (a) any person named in the complaint; (b) anyone who reports directly to such a person; and (c) anyone with a potential conflict of interest in the outcome.
- Determine which body will oversee the investigation (the full Board, the Audit Committee, or a specially constituted committee) based on who is implicated and the seriousness of the allegations. Where senior management is implicated, the Audit Committee or Board should oversee the investigation directly.
- Issue a document preservation notice (litigation hold) immediately: suspend routine document deletion, log rotation, automatic backup overwrites, and device wiping across relevant systems and custodians. Confirm compliance in writing from IT.
- Assess disclosure obligations at the outset. Consider materiality thresholds for stock exchange disclosure under Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015 (SEBI LODR); the statutory auditor’s independent reporting obligations under ; and, in cross-border matters, disclosure requirements across all relevant jurisdictions.
3. Structuring the investigation
- Issue a written investigation mandate before work begins. The mandate must specify the scope of the inquiry, the identity of the investigation lead, the party instructing the investigation team, reporting lines, key milestones, and the approved budget.
- Define the scope clearly at the outset. Build in a formal mechanism (requiring approval from the oversight body) to expand the scope where new evidence justifies it.
- Engage external legal counsel to lead or supervise the investigation so that legal professional privilege is preserved to the fullest extent available under applicable law. Internal counsel should not lead the investigation where privilege is a concern.
- Retain forensic accountants and technology experts through external legal counsel, not directly by the company, to protect their work product under legal privilege.
- Agree on reporting protocols in the mandate: who the investigation team reports to, the frequency and format of interim updates to the oversight body, and how final findings will be presented.
4. Preserving legal privilege
- Indian law does not extend legal professional privilege to in-house counsel. Only communications with an external advocate enrolled with a Bar Council attract advocate-client privilege under Section 132 of the . The implications of this must be factored into how the investigation is structured from the start.
- Maintain a strict separation between legal advice (which may attract privilege) and factual investigation records (which generally do not). Do not commingle these in the same document or communication.
- There is no concept of partial waiver under Indian law. Any voluntary disclosure of privileged material, including selective disclosure to a regulator, risks waiving privilege over all communications on the same subject matter. Each disclosure decision must be taken with counsel.
- Privilege does not attach to communications made in furtherance of a crime or fraud. This exclusion is expressly set out in the , and applies regardless of who authored the communication.
- In cross-border investigations, assess privilege on a jurisdiction-by-jurisdiction basis. The rules differ materially between India, the US (attorney-client privilege), the UK (legal professional privilege), and the EU. Work with counsel in each relevant jurisdiction before sharing privileged material across borders.
5. Evidence and digital integrity
- Issue written preservation notices to identified custodians and the IT team, specifying the categories of data to be retained, the relevant time period, and the systems covered.
- Suspend automatic deletion, backup overwrites, and routine data purges from the moment the investigation is initiated, and maintain this suspension throughout the investigation.
- Collect electronic evidence using forensically sound methods. Maintain a documented chain of custody for all evidence collected, recording who collected it, from what source, when, and in what format.
- Keep evidence collection proportionate to the allegations. Ensure that collection practices comply with applicable privacy obligations, including the , and any sector-specific data protection requirements.
- Before transferring investigation data outside India, seek legal advice on applicable data localisation requirements and cross-border transfer conditions under the Digital Personal Data Protection Act, 2023 (which applies to a government-notified restricted-country list), and any relevant sector-specific regulations (for example, those governing financial data or health records).
6. Interviews
- Before each interview, external counsel must give the interviewee an Upjohn warning, i.e., a clear statement that (a) counsel represents the company, not the individual; (b) the interview is confidential and protected by the company’s privilege, which the company (not the individual) may choose to waive; and (c) the employee should not discuss the interview with colleagues/anyone else within the organisation.
- Sequence interviews in accordance with the investigation plan. As a general rule, interview peripheral witnesses before key witnesses, and key witnesses before persons who are the subject of the allegations.
- Conduct all interviews under a formally approved interview protocol that provides for legal oversight of each session, a consistent approach to questioning, a fair opportunity for the interviewee to respond, and contemporaneous documentation of what was said.
- Give individuals who are the subject of allegations a meaningful opportunity to respond to the evidence before the investigation team reaches its conclusions. This is a requirement of procedural fairness and may be relevant to the admissibility of findings in subsequent proceedings.
- Do not offer confidentiality, immunity from disciplinary action, or any form of protection unless this has been specifically authorised by the oversight body and is legally permissible in the circumstances.
- Maintain interview notes and legal analysis under the supervision of external counsel to preserve any applicable privilege.
7. Reporting and disclosure
- Counsel must ensure that the investigation findings are presented to the Audit Committee or Board in the format specified in the investigation mandate. Reports should clearly distinguish between: (a) factual findings; (b) legal analysis; and (c) recommendations. Do not conflate these.
- Assess disclosure obligations promptly as material findings emerge. Any public statement or disclosure (including filings with stock exchanges under SEBI (LODR)) must be accurate, complete, and consistent with what has been communicated to regulators.
- Align legal and communications strategy from an early stage. Engage PR advisors in parallel with the legal process, and ensure that all external communications (including press statements, internal announcements, and investor communications) are reviewed and approved by legal counsel before release.
- Coordinate with the Company Secretary, Finance team, and statutory auditor on applicable fraud reporting obligations, including reporting to the Central Government under Section 143(12) of the Companies Act, 2013 and the related .
- Assess reporting obligations to sectoral regulators (RBI, SEBI, IRDAI, or others depending on the company’s activities) and identify any data breach notification timelines if personal data has been compromised under the Digital Personal Data Protection Act, 2023.
- Treat any voluntary disclosure to a regulator as a privilege decision. The scope, format, and content of such disclosure must be agreed with external counsel before it is made.
- In cross-border matters, assess regulatory exposure across all relevant jurisdictions at the earliest opportunity. Where agencies such as the US Department of Justice, the SEC, the UK Serious Fraud Office, or the FCA may have jurisdiction, engage local counsel in those jurisdictions promptly.
8. Remediation and close-out
- Remediation must address the root cause of the misconduct, not just the immediate incident. Where a control failure is identified, the control itself must be fixed and not merely the individual instance that was investigated.
- Take proportionate disciplinary action against those found responsible. Record in writing the rationale for every disciplinary decision, including decisions not to take action.
- Assign named owners and fixed timelines for remediating each internal control deficiency identified during the investigation. Track these to completion and report progress to the Audit Committee.
- Take visible, active steps to protect complainants from retaliation, both during the investigation and after it closes. Document these steps.
- Preserve the complete investigation record (preservation notices, evidence logs, interview notes, legal advice, and final reports) for the period required by applicable legal, regulatory, and document retention obligations.
- Relevant investigating team must brief the Board on the closure of the investigation, key lessons learnt, root cause findings, and any proposed changes to investigation protocols, compliance policies, or internal controls. This brief should be formally recorded in the Board minutes.
9. Additional safeguards for listed companies: SEBI compliance
Investigations at listed companies carry a second layer of obligations that private companies don’t have. Get this wrong and the fallout may involve a stock exchange filing, a media story, and a regulator asking questions you haven’t prepared for yet.
- Assess materiality the moment the allegation touches anything disclosable. Under Regulation 30 of , an event is material if it crosses 2% of turnover, 2% of net worth, or 5% of the average of the last three years’ profit or loss after tax, whichever threshold applies to the nature of the event. Don’t wait for the investigation to conclude before running this test. Run it early, and run it again as facts develop.
- Know your clock the moment materiality is triggered. Disclosure is due within 30 minutes of the board meeting where the decision was taken, 12 hours from the event if it originates within the company, or 24 hours if it originates outside the company. These timelines are tight and unforgiving. Build them into the investigation plan from day one, and not as an afterthought once the report is ready.
- If the company is among the top 250 listed entities by market capitalisation, monitor media reports and market rumours actively. Where a rumour about the investigation circulates and looks specific rather than general, the company may be required to confirm, deny, or clarify within 24 hours of the report, whether or not it planned to say anything publicly.
- Check whether the allegation touches unpublished price sensitive information. If it does, the SEBI (Prohibition of Insider Trading) Regulations kick in alongside the investigation itself. Forthwith close the trading window for relevant insiders as needed and where appropriate, restrict access to the facts on a need-to-know basis, and log everyone who has access in the Structured Digital Database as required under the Securities and Exchange Board of India (Prohibition of Insider Trading) Regulations 2015 (PIT Regulations).
- Route the investigation through the existing vigil mechanism and Audit Committee oversight structure required under applicable Regulations of the LODR.
- If the investigation reveals a related party transaction (RPT) that wasn’t previously disclosed or approved, treat this as a separate compliance failure requiring its own assessment, not a subset of the main investigation. RPT disclosure and approval lapses under the LODR carry their own reporting consequences.
- Where the investigation results in a fine, penalty, or adverse regulatory order, check the disclosure threshold carefully.
- Keep the Audit Committee and, where required, the Board itself briefed on disclosure decisions as they’re made, not just at the end. A disclosure decision taken without a documented key stakeholder view is a governance gap that surfaces later, usually at the worst possible time.
- Where the investigation is ongoing and a disclosure obligation has already crystallised, you may disclose what is known and factual at that point, and follow up as the matter develops. Of course the strategy and overall disclosure decision may vary, depending on the specific facts and circumstances of the matter.
About the author
Tanya Ganguli is the founder of TG Law Offices. The practice is super-specialist, having a pan-India presence focused on governance, investigations and white-collar defence. Tanya has led internal investigations and regulatory defense work for Fortune 500 and DAX 40 companies, financial institutions, and CXOs across bribery, fraud, employment and internal-controls matters. She is ranked a Global Elite Thought Leader by Lexology Who’s Who Legal and recognised by The Legal 500.
This article was compiled with research assistance from Yash Bhatnagar and Soumyaditya Deb.