{"description":"Fraud & Forensic Investigation Engagement as a decision-aware workflow. It runs on a dedicated Audit item (audit_type: investigation) created for this allegation at intake — the confidential case record — with the workflow instance attached to that item and its visibility restricted to the named investigation team. In scope: one specific fraud allegation, worked predication-gated and confidentially from intake through evidence preservation, forensic procedures, interviews, loss quantification, and audit-committee reporting; the named deliverables are the chain-of-custody register, the findings memorandum with its loss-quantification schedule, and the privilege-marked audit-committee fraud report. Out of scope: the enterprise fraud risk profile (owned by Fraud Risk Assessment & Anti-Override Control Review, which receives scheme intelligence from this case rather than being rerun here) and any unrelated conduct discovered in passing (which gets its own intake record). It consumes the hotline intake package from Control Responsibility Communications & Ethics Hotline when so routed, and hands each control breakdown off as an Issue item — control-gap findings to Finding Remediation & Action-Plan Monitoring and ICFR-affecting deficiencies to SOX Deficiency Remediation — rather than duplicating that work.","edges":[{"id":"e-assess-predication-develop-investigation-plan","label":"Investigate","source":"assess-predication","target":"develop-investigation-plan","whenValue":"investigate"},{"id":"e-assess-predication-refer-to-hr-or-legal","label":"Refer","source":"assess-predication","target":"refer-to-hr-or-legal","whenValue":"refer_hr_legal"},{"id":"e-assess-predication-document-closure-rationale","label":"Close","source":"assess-predication","target":"document-closure-rationale","whenValue":"close_insufficient"},{"id":"e-develop-investigation-plan-issue-litigation-hold-and-preserve-evidence","source":"develop-investigation-plan","target":"issue-litigation-hold-and-preserve-evidence"},{"id":"e-issue-litigation-hold-and-preserve-evidence-execute-forensic-procedures","source":"issue-litigation-hold-and-preserve-evidence","target":"execute-forensic-procedures"},{"id":"e-execute-forensic-procedures-conduct-witness-interviews","source":"execute-forensic-procedures","target":"conduct-witness-interviews"},{"id":"e-conduct-witness-interviews-conduct-subject-interview","source":"conduct-witness-interviews","target":"conduct-subject-interview"},{"id":"e-conduct-subject-interview-develop-findings-and-quantify-loss","source":"conduct-subject-interview","target":"develop-findings-and-quantify-loss"},{"id":"e-develop-findings-and-quantify-loss-determine-external-referral","source":"develop-findings-and-quantify-loss","target":"determine-external-referral"},{"id":"e-determine-external-referral-execute-external-referral","label":"Referral required","source":"determine-external-referral","target":"execute-external-referral","whenValue":"external_required"},{"id":"e-determine-external-referral-handoff-remediation-and-control-gaps","label":"Internal only","source":"determine-external-referral","target":"handoff-remediation-and-control-gaps","whenValue":"internal_only"},{"id":"e-execute-external-referral-handoff-remediation-and-control-gaps","source":"execute-external-referral","target":"handoff-remediation-and-control-gaps"},{"id":"e-handoff-remediation-and-control-gaps-evaluate-disclosure-and-lessons","source":"handoff-remediation-and-control-gaps","target":"evaluate-disclosure-and-lessons"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{"UC-AUDIT-05":"operates","UC-AUDIT-08":"operates","UC-AUDIT-12":"operates","UC-AUDIT-13":"operates","UC-AUDIT-14":"operates","UC-AUDIT-15":"operates","UC-AUDIT-16":"operates","UC-AUDIT-18":"operates","UC-IR-07":"operates"},"controls":["UC-AUDIT-05","UC-AUDIT-08","UC-AUDIT-12","UC-AUDIT-13","UC-AUDIT-14","UC-AUDIT-15","UC-AUDIT-16","UC-AUDIT-18","UC-IR-07"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-fraud-investigation","contentDigest":"sha256:b5fe4ec3e78e34833795d4e184e8ffaddf20825dd6fd5fa09a4a661495cc0862","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:b5fe4ec3e78e34833795d4e184e8ffaddf20825dd6fd5fa09a4a661495cc0862","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-fraud-investigation"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"audit-fraud-investigation","source":"coworkcanvas-gallery","standards":["iia-2024"],"teams":["internal-audit","compliance-legal"]},"name":"Fraud & Forensic Investigation Engagement","nodes":[{"data":{"decisionField":"predication_path","description":"Determine whether discreetly corroborated allegation facts justify investigation, referral or closure without intrusive unsupported action.","formData":{"fields":[{"key":"predication_path","label":"Assess predication and triage","options":[{"label":"Predication supports investigation","value":"investigate"},{"label":"Refer to HR or Legal ownership","value":"refer_hr_legal"},{"label":"Close with documented rationale","value":"close_insufficient"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Determine whether discreetly corroborated allegation facts justify investigation, referral or closure without intrusive unsupported action.\n\n**Inputs**\nThe intake package and trigger record for this allegation: the trigger captured verbatim (whistleblower or ethics-hotline report, management or board referral, external-auditor or regulator inquiry, or a monitoring anomaly), the intake source, and the receipt date. When the matter is routed from the hotline, this consumes the handoff package from Control Responsibility Communications & Ethics Hotline — reporter channel, receipt date, verbatim allegation, and any triage already performed.\n- The investigation protocol's case-numbering and confidentiality-marking conventions.\n- The named investigation team roster, even if still provisional.\n\n**Decision criteria**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive or delegate consulting counsel owns the stated judgments and authorizations.*\n\n*Register case and restrict access.* Open a confidential case record that captures the allegation exactly as received, classifies the alleged scheme, and locks the file to the named team — protecting the reporter, the subject's due process, and the integrity of any later disciplinary or legal proceeding.\n\n1. Assign the case reference from the protocol's numbering scheme and use it — never subject names — in file names, calendar entries, and correspondence, so a stray subject line cannot tip anyone off.\n2. Capture the allegation facts as received, without embellishment or interpretation: who is alleged to have done what, when, how, and the amounts if stated. Quote the reporter's own words; mark investigator inference separately. What is written now becomes the baseline every later conclusion is measured against.\n3. Classify the alleged scheme using the occupational-fraud taxonomy — fraudulent financial reporting, asset misappropriation, or corruption — and the sub-scheme where evident (billing, expense reimbursement, payroll, skimming, kickbacks, bid rigging). Classification drives which analytics, records, and custodians matter downstream.\n4. Identify the implicated entities, processes, accounts, and personnel, including each subject's role, system access, and approval authority — these define the tip-off risk and the provisional custodian list.\n5. Restrict the case file to the named investigation team on a strict need-to-know basis: restricted item visibility, no shared-drive copies, a distribution list of named individuals only. Apply the confidentiality markings the audit function's obligations require for information obtained in its work, and take no action — access checks in the subject's area, pointed questions, unusual record requests — that could alert a potential subject.\n6. Log the intake source, receipt date, and the acknowledgment sent back to the reporting channel: acknowledge receipt within a couple of business days without disclosing what happens next.\n\n*Assess predication and triage.* Resolve whether the totality of circumstances would lead a reasonable, professionally skeptical reviewer to conclude that a fraud may have occurred, is occurring, or may occur — and route the matter accordingly. Predication gates the investigation: suspicion alone never justifies investigative intrusion, and seniority of the subject never justifies closure. Owned by the CAE or delegate, with general counsel consulted on privilege-sensitive matters.\n\n\n\n**investigate** (Predication supports investigation) — the allegation is specific enough to test (identifiable actors, mechanism, period, or accounts) AND at least one corroborating indicator exists from discreet preliminary checks: records consistent with the allegation, a quick analytic showing the claimed anomaly, a pattern of prior allegations against the same subject or process, or a credible first-hand reporter with direct knowledge. The alleged conduct, if true, would constitute fraud — intentional deception for gain — within the function's investigative mandate. Matters implicating senior management take this branch with the audit committee informed at once, regardless of preliminary-check results.\n- **refer_hr_legal** (Refer to HR or Legal ownership) — the facts as alleged, even if fully true, are not fraud: workplace conduct, harassment, interpersonal or performance matters (HR owns), or legal and regulatory questions without a deception-for-gain element (Legal or Compliance owns). Also the right branch when a conflict of interest disables internal audit from investigating objectively and another function or an external party must lead.\n- **close_insufficient** (Close with documented rationale) — after reasonable, discreet clarification attempts the allegation remains too vague to test; or the checked records affirmatively contradict it; or it duplicates a matter already investigated and resolved and brings no new facts. Closure requires documenting exactly what was checked — an unchecked allegation is never \"insufficient\".\n\nPreliminary checks must stay discreet: existing records, prior audit work, and system data only — no interviews of the subject's colleagues, no unusual record requests to the subject's area.\n\n**Record in AssureSwarm**\nCreate the case as an **Audit** item (`audit_type: investigation`): the case reference and scheme classification in `description`, the implicated entities, processes, accounts, and personnel in `scope`, the lead investigator in `lead_auditor`, and the scheme window in `period_start`/`period_end`; restrict the item's visibility to the named investigation team.\n- Link the case Audit item to the affected **Process** item(s) in scope and to each implicated **Control** item (item relationships Audit ↔ Process, Audit ↔ Control).\n- Attach the verbatim allegation record and the acknowledgment as step documents; where the matter was routed from the hotline, link the incoming allegation record from that intake handoff.\n\nSubmit this step's form: `predication_path` = the chosen branch; the step result = the specific facts checked, sources consulted, and the corroborating or contradicting indicators, with references to attached evidence; the step's approver record = the CAE or delegate who made the call.\n\n**Exit criteria**\nCase reference assigned; allegation captured verbatim and separated from investigator inference; scheme classified; the access restriction verified by checking who can actually open the record; acknowledgment logged; no subject-alerting action taken.\n\nForm submitted with a rationale that cites checked facts rather than conclusions; audit-committee notification recorded where senior management is implicated; unused branches are prunable.","kind":"decision","label":"Assess predication and triage"},"id":"assess-predication"},{"data":{"description":"Accept ownership, confidentiality and anti-retaliation duties and commit to formal outcome reporting.","instructions":"**Objective** — Accept ownership, confidentiality and anti-retaliation duties and commit to formal outcome reporting.\n\n**Inputs**\nThe intake record, triage assessment, and predication rationale from the decision step.\n- Any records or preliminary-check evidence gathered so far.\n- The disciplinary-process and case-management contacts in HR and Legal.\n\nThe complete file for the selected case path: intake and triage evidence plus the applicable custody register, workpapers, memoranda, reports, referral and handoff records. A referred or predication-closed case retains only artifacts actually produced; do not invent investigation results.\n- Active litigation holds and open referral obligations; the retention schedule.\n- Final dispositions: findings, referrals, disciplinary and recovery outcomes.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Named receiving HR or Legal owner owns the stated judgments and authorizations.*\n\n*Refer matter to HR or Legal.* Transfer a matter internal audit should not lead to the function accountable for it, with a package complete enough that the receiving owner can act without re-intake, and with the reporter's protections intact.\n\n1. Assemble the referral package: the verbatim allegation, intake metadata, the triage assessment with its rationale, and every record examined — labeled so the receiving function knows what was and was not checked. Do not editorialize on guilt; transfer facts and open questions.\n2. Document the referral basis (why HR or Legal owns this) and obtain a named receiving owner — a person, not a mailbox. Record their written acceptance and its date; an unacknowledged referral is not a transfer.\n3. Transfer under confidentiality: reporter identity disclosed only where the receiving process genuinely requires it and the intake channel's commitments permit it; anti-retaliation protections restated to the receiving owner in writing.\n4. Where the matter alleges a policy violation, confirm it enters the formal disciplinary process — not an informal manager conversation — and agree in writing how the outcome and any sanction will be reported back to internal audit, so the disciplinary control's operation for this matter is verifiable end to end.\n5. Retain the referral package and acknowledgment in the case file, set a follow-up checkpoint to confirm the outcome report-back arrives, then close the internal audit case.\n\n*Close and archive.* Close the engagement with the case file preserved as an immutable, privilege-intact record, every linked obligation dispositioned, and follow-ups scheduled — so the file can be reopened, produced, or relied on years later without reconstruction.\n\n6. Verify completion honestly: every step finished or explicitly dispositioned, decision forms submitted, handoffs acknowledged, and external obligations either closed or carried by a named owner with a next date. Closing over an open obligation is how insurer deadlines and re-test commitments get missed.\n7. Archive the complete file produced on this selected case path with privilege markings and access restrictions intact — archiving never means relaxing access. The confidentiality ring survives closure.\n8. Confirm nothing subject to an active litigation hold or referral obligation is destroyed; set the retention clock from the last obligation to lapse (hold release, claim settlement, end of prosecution), not from the case close date, and record counsel's written hold-release instruction when it comes.\n9. Update the linked records with the final disposition: findings status, referral outcomes, disciplinary records, and the allegation record back at intake — so the hotline's history and any future predication assessment see how this matter ended.\n10. Communicate closure to the accountable stakeholders — the CAE, general counsel, the audit-committee record, and the receiving workflow owners — without expanding the confidentiality ring.\n11. Schedule the follow-up checkpoints that outlive the case: remediation progress in Finding Remediation & Action-Plan Monitoring, SOX Deficiency Remediation severity outcomes, and external-referral and recovery milestones. Lock the workflow record; post-closure edits happen as documented amendments, never silent changes.\n\n**Record in AssureSwarm**\nAttach the referral package and the written acknowledgment as step documents (DOCX/PDF); the receiving owner, function, and acceptance date live in that package — Audit has no native referral field.\n- Set a follow-up checkpoint for the outcome report-back and note the confidentiality terms applied on this step; set the case Audit item status to reflect the transfer out.\n\nArchive the workflow instance as the durable audit trail and set the case **Audit** item to its final status with access restrictions intact; record the retention basis, hold status, and closure-communication recipients with dates on this step.\n- Confirm the linked **Issue** (findings), referral, disciplinary, and recovery records reflect final dispositions, and update the allegation record back at intake; schedule the follow-up checkpoints.\n\n**Exit criteria**\nReferral package transferred and acknowledged by a named owner; disciplinary-process entry confirmed where applicable; the outcome report-back mechanism is agreed in writing; reporter protections documented; the case file retains the full referral evidence.\n\nAll steps and obligations dispositioned; the case file is archived with privilege and access controls intact; retention is anchored to the last obligation to lapse; linked records are final; follow-ups are scheduled with owners; the record is locked against silent edits.","label":"Refer matter to HR or Legal"},"id":"refer-to-hr-or-legal"},{"data":{"description":"Independently challenge and approve the checked-fact rationale for closing an allegation without investigation.","instructions":"**Objective** — Independently challenge and approve the checked-fact rationale for closing an allegation without investigation.\n\n**Inputs**\nThe intake record and the predication decision with its rationale.\n- The specific records, systems, and prior-case history consulted during triage.\n- The retention schedule for investigation records and the hotline's disposition-notification conventions.\n\nThe complete file for the selected case path: intake and triage evidence plus the applicable custody register, workpapers, memoranda, reports, referral and handoff records. A referred or predication-closed case retains only artifacts actually produced; do not invent investigation results.\n- Active litigation holds and open referral obligations; the retention schedule.\n- Final dispositions: findings, referrals, disciplinary and recovery outcomes.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive or delegate independent of the original triager owns the stated judgments and authorizations.*\n\n*Document closure rationale.* Close an allegation that does not meet the predication threshold with a record defensible to a later reviewer — including a regulator or plaintiff's counsel asking, years on, why this was not investigated.\n\n1. Write the closure memo to the standard of a skeptical future reader: the allegation as received, each fact checked, each source consulted (system, report, prior case), what each showed, and why the totality falls short of predication. \"Nothing found\" is not a rationale; \"vendor master shows no employee-address or bank-account match for the named vendor across the alleged period, and the named approver had no system access to the cited account\" is.\n2. Have someone other than the triager — the CAE or delegate — review and approve the closure. Single-person closure of fraud allegations is itself a control weakness.\n3. Retain the intake record, triage evidence, and closure memo under the retention schedule; closed-allegation files are the pattern library that makes repeat allegations visible.\n4. Set the monitoring trigger: watchlist entries on the subject, process, and entity so any future allegation resurfaces this history at intake. Two individually insufficient allegations against the same subject often establish predication together.\n5. Notify the intake channel of the disposition — reviewed and closed — without disclosing investigative detail or triage methods, preserving both reporter confidence in the channel and the subject's confidentiality.\n\n*Close and archive.* Close the engagement with the case file preserved as an immutable, privilege-intact record, every linked obligation dispositioned, and follow-ups scheduled — so the file can be reopened, produced, or relied on years later without reconstruction.\n\n6. Verify completion honestly: every step finished or explicitly dispositioned, decision forms submitted, handoffs acknowledged, and external obligations either closed or carried by a named owner with a next date. Closing over an open obligation is how insurer deadlines and re-test commitments get missed.\n7. Archive the complete file produced on this selected case path with privilege markings and access restrictions intact — archiving never means relaxing access. The confidentiality ring survives closure.\n8. Confirm nothing subject to an active litigation hold or referral obligation is destroyed; set the retention clock from the last obligation to lapse (hold release, claim settlement, end of prosecution), not from the case close date, and record counsel's written hold-release instruction when it comes.\n9. Update the linked records with the final disposition: findings status, referral outcomes, disciplinary records, and the allegation record back at intake — so the hotline's history and any future predication assessment see how this matter ended.\n10. Communicate closure to the accountable stakeholders — the CAE, general counsel, the audit-committee record, and the receiving workflow owners — without expanding the confidentiality ring.\n11. Schedule the follow-up checkpoints that outlive the case: remediation progress in Finding Remediation & Action-Plan Monitoring, SOX Deficiency Remediation severity outcomes, and external-referral and recovery milestones. Lock the workflow record; post-closure edits happen as documented amendments, never silent changes.\n\n**Record in AssureSwarm**\nAttach the closure memo (DOCX/PDF) and triage evidence as step documents; the approver and closure date live in the memo — record them there.\n- There is no native watchlist surface: capture the subject, process, and entity as searchable keywords in the case Audit item `description` (and the closure memo) so a future allegation resurfaces this history at intake, and record the disposition notice sent to the intake channel on this step.\n- Set the case Audit item status to closed-without-investigation.\n\nArchive the workflow instance as the durable audit trail and set the case **Audit** item to its final status with access restrictions intact; record the retention basis, hold status, and closure-communication recipients with dates on this step.\n- Confirm the linked **Issue** (findings), referral, disciplinary, and recovery records reflect final dispositions, and update the allegation record back at intake; schedule the follow-up checkpoints.\n\n**Exit criteria**\nClosure memo cites the specific facts checked and sources consulted; independent approval recorded; retention applied; watchlist triggers set for repeat allegations; intake channel notified without investigative detail.\n\nAll steps and obligations dispositioned; the case file is archived with privilege and access controls intact; retention is anchored to the last obligation to lapse; linked records are final; follow-ups are scheduled with owners; the record is locked against silent edits.","label":"Document closure rationale"},"id":"document-closure-rationale"},{"data":{"description":"Authorize a falsifiable investigation theory, lawful scope, conflict-free team, privilege posture, custodians and sequencing before evidence handling.","instructions":"**Objective** — Authorize a falsifiable investigation theory, lawful scope, conflict-free team, privilege posture, custodians and sequencing before evidence handling.\n\n**Inputs**\nThe case record: allegation, scheme classification, implicated entities, processes, accounts, and personnel.\n- The predication memo and preliminary-check evidence.\n- Prior audits, walkthroughs, and control documentation for the affected process (prior **Audit** items and the affected **Process**/**Control** items); the code of conduct, the specific policies, and the delegations of authority as **Policy** items in the policy library.\n\nThe proposed team roster: investigators, forensic specialists, and any external providers.\n- The subjects' identities, business area, and reporting chain from the case record.\n- General counsel's availability and the organization's privilege conventions; the workplan's provisional custodian list.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Independent investigation supervisor and general counsel owns the stated judgments and authorizations.*\n\n*Develop investigation plan.* Convert predication into an approved, risk-based workplan — objectives, scope, evaluation criteria, sequenced procedures, resources, and a communication protocol — so fieldwork tests a fraud theory rather than wandering, and holds up to later scrutiny.\n\n1. Perform an engagement-level risk assessment of the allegation: what is the worst credible version of this scheme, over what period, through which accounts and systems, and who else could be involved? Plan to the credible worst case and narrow on evidence — planning to the narrow allegation misses the scheme's real footprint.\n2. State the fraud theory: a falsifiable hypothesis of who did what, how, and where it would leave traces. Every procedure in the plan should corroborate or refute an element of it; revise the theory as evidence lands.\n3. Define the investigation objectives, the period and entities in scope, and the evaluation criteria: the code of conduct and the specific policies, delegations of authority, accounting requirements, and laws and regulations the alleged conduct would violate. Findings are conclusions against criteria — vague criteria produce unusable findings.\n4. Design and sequence the procedures: preservation and covert data work first, document examination and analytics next, witness interviews after the documentary picture is formed, subject interviews last. Flag which procedures risk alerting a subject and gate them accordingly.\n5. Determine resources: forensic accounting, digital forensics, eDiscovery tooling, external counsel, or external investigators where independence, skills, or privilege demand them. Estimate effort and elapsed time honestly — preservation and collection deadlines drive everything else.\n6. Set the communication protocol: the named individuals who know the investigation exists, the code name used in scheduling and correspondence, and the escalation path for interim discoveries such as an ongoing loss requiring immediate containment.\n7. Obtain supervisory approval of the workplan before fieldwork begins; scope changes after approval are documented amendments, not silent drift.\n\n*Confirm team independence and privilege posture.* Ensure the people touching the case are conflict-free and the legal-privilege posture and custodian list are fixed before any evidence is handled — objectivity defects and privilege mistakes discovered later can taint everything already collected.\n\n8. Screen every team member and engaged specialist for conflicts against the subjects, the business area under investigation, and its reporting chain: personal relationships, prior roles in the affected process, financial interests, and reporting-line dependencies. Collect signed conflict declarations; recuse and replace anyone impaired, and record the recusal rather than quietly reshuffling.\n9. Confirm objectivity safeguards: supervision of the investigation by someone outside the affected area's chain, and no team member reviewing work they previously performed or approved.\n10. Determine the privilege posture with general counsel: whether the work proceeds at the direction of counsel in anticipation of litigation. If privileged, record the counsel-direction memo, apply the case-file labeling convention (for example \"Privileged & Confidential — Prepared at the Direction of Counsel\") consistently — inconsistent marking is how privilege gets pierced — and brief the team that the privilege belongs to the organization, not to individuals, and is waived by careless distribution.\n11. If the work is not privileged, record that decision too, with counsel's rationale; a posture chosen by default is indefensible either way.\n12. Finalize the custodian list: the people and the systems (mailboxes, file shares, ERP modules, expense and payroll systems, logs, badge systems) whose records the investigation will preserve and collect, with a tip-off-risk rating per custodian that drives whether preservation is announced or silent.\n\n**Record in AssureSwarm**\nAttach the approved workplan (DOCX/PDF) covering objectives, scope, criteria, fraud theory, procedure sequence, resources, and the communication protocol as a step document; record the approver and approval date on this step.\n- Link the evaluation-criteria **Policy** items the alleged conduct would violate — the code of conduct, the specific policies, and the delegations of authority (`policy_type: policy`/`standard`/`procedure`, mapped by `framework`/`domains`) — to the case Audit item so findings conclude against named criteria; the internal investigation protocol itself has no native home and stays a step document.\n\nAttach the conflict declarations, the recusal log if any, the privilege-determination memo, and the finalized custodian list with tip-off-risk ratings as step documents.\n- The privilege posture and labeling convention have no native Audit field — record them in the privilege-determination memo and note the posture in the case Audit item `scope` so every later step inherits it.\n\n**Exit criteria**\nWorkplan approved before fieldwork starts; the fraud theory is stated and falsifiable; criteria are specific enough to conclude against; procedure sequencing protects against tip-off; resource needs and the informed-persons list are explicit.\n\nEvery team member has a recorded conflict screen; impaired members recused and replaced; the privilege posture is documented with counsel either way; the labeling convention is set; the custodian list is final with per-custodian tip-off risk.","label":"Develop investigation plan"},"id":"develop-investigation-plan"},{"data":{"description":"Issue the litigation hold and preserve in-scope records before collection begins","formData":{"fields":[{"key":"hold_acknowledged","label":"I have read the hold notice, will preserve the records described, and will not delete, alter, or discuss the matter","required":false,"type":"checkbox"},{"key":"records_in_your_control","label":"Records, devices, mailboxes, and storage locations within the described scope that you control","required":false,"type":"textarea"},{"key":"copies_outside_company_systems","label":"Any in-scope copies held outside company systems (personal device, personal cloud, paper files)","required":false,"type":"textarea"},{"key":"deletion_since_scope_period","label":"Has anything in scope been deleted, archived, or overwritten since the period began?","options":[{"label":"None known","value":"none_known"},{"label":"Possibly, through routine retention or auto-deletion","value":"routine_retention"},{"label":"Yes — described below","value":"yes"}],"required":false,"type":"select"},{"key":"deletion_details","label":"What was deleted or changed, when, and by what process","required":false,"type":"textarea"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Freeze every record the allegation could touch before collection begins, so nothing relevant is deleted by routine retention, housekeeping, or a tipped-off subject — spoliation discovered later undermines both the case and the organization's litigation position.\n\n**Inputs**\n- The finalized custodian list with tip-off-risk ratings.\n- Counsel's litigation-hold template and the privilege posture.\n- IT contacts for mail, file storage, financial systems, and log platforms; the retention schedules currently running against in-scope data.\n\n**Procedure**\n1. With counsel, issue the litigation hold to custodians rated safe to notify: the scope of records to preserve, the prohibition on deletion or alteration, the instruction not to discuss the matter, and a required written acknowledgment — assign this step's form alongside the notice so the acknowledgment comes back structured and dated. Track acknowledgments to completion and chase non-responders; an unacknowledged hold protects nothing.\n2. For custodians who are subjects or tip-off risks, apply silent preservation through IT instead: administrative mailbox holds, snapshots of file shares and home directories, and preservation of system accounts — executed by named IT staff who are themselves inside the confidentiality ring. Send no form to these custodians.\n3. Suspend automated deletion and retention expiry for in-scope mailboxes, file stores, financial systems, and logs, and confirm the suspension took effect with evidence — a screenshot or export of the hold configuration, not an email promising it.\n4. Open the chain-of-custody log that every preserved and collected item will carry from this point: item, source custodian or system, who touched it, when, and why.\n5. Verify that audit logs for in-scope systems were protected and retained for the full review period. Where log retention already lapsed or logs show integrity failures, record that as a control exception in its own right — a finding about the logging control, independent of the fraud conclusion — and adjust the fraud theory for the evidence gap.\n6. Diary the hold: periodic re-confirmation to custodians, and release only on counsel's written instruction after the last obligation lapses.\n\n**Record in AssureSwarm**\n- The form on this step, answered by each notified custodian, uses the named custodian roster and hold-notice reference as assignment context and captures the acknowledgment itself, the in-scope records and locations they control, any copies held outside company systems, whether anything in scope has been deleted or overwritten and how, with the native submission timestamp recording acknowledgment. Its returns are the acknowledgment tracker; disclosed deletions route straight into item 5's evidence-gap assessment.\n- Attach the hold notice, silent-preservation confirmations, and the retention-suspension evidence as step documents.\n- Open the chain-of-custody register as a step document (XLSX/CSV). Where audit-log retention lapsed, log it as an **Issue** item (`issue_type: exception`, `source: internal_audit`, `severity`) linked to the affected **Control** (Issue ↔ Control) — a control finding independent of the fraud conclusion.\n\n**Exit criteria** — Every custodian is covered by an acknowledged hold or a confirmed silent preservation; retention suspension is verified with evidence; the chain-of-custody log is open; log-retention gaps are recorded as control exceptions; hold re-confirmation is diarized.\n\n**Form recipient** — Safe-to-notify record custodian outside the investigation execution team. Check the complete preparation, execution, review and approval roster first: anyone assigned a role anywhere in this workflow contributes through native results, documents and approvals instead. Read current evidence and declarations before requesting anything. Select only unresolved questions for the identified scope and period; known facts remain linked context, and no request is needed if nothing is missing. The catalog fields are optional so known or unasked facts need not be repeated; every question actually required by the assignment must have an attributable response or a recorded unresolved gap before the dependent judgment. A negative or declined affirmation remains visible; it must never be converted to a positive statement. Notified record custodians disclose preservation facts and acknowledge the hold; they do not execute the investigation. Named investigators, counsel and preservation IT staff use native work records, and subjects or tip-off-risk custodians receive no form.","label":"Issue litigation hold and preserve evidence"},"id":"issue-litigation-hold-and-preserve-evidence"},{"data":{"description":"Assess authenticity, corroboration and alternative explanations using traceable acquired evidence and reproducible analytics.","instructions":"**Objective** — Assess authenticity, corroboration and alternative explanations using traceable acquired evidence and reproducible analytics.\n\n**Inputs**\nThe custodian list, preservation confirmations, and the open chain-of-custody log.\n- Digital-forensics capability (internal or engaged) with imaging tooling and write blockers.\n- The restricted case repository and its access list.\n\nThe verified working copies: journal entries, payments, vendor master, expense and payroll data, logs, communications.\n- The fraud theory and scheme classification from the workplan.\n- The delegation-of-authority thresholds and policy criteria; the chain-of-custody register.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Forensic examiner and investigation lead owns the stated judgments and authorizations.*\n\n*Collect and forensically image evidence.* Collect records and devices so their integrity, provenance, and chain of custody survive disciplinary proceedings, insurance claims, and court — evidence handled sloppily here is evidence lost, no matter what it proves.\n\n1. Forensically image in-scope devices — laptops, phones, removable media — before anyone browses them: write-blocked acquisition, a cryptographic hash (SHA-256) computed at capture, and the hash recorded in the custody log. Opening files on the original changes timestamps and destroys the metadata story.\n2. Collect per the custodian list: mailboxes, chat and collaboration exports, system and application logs, financial records and journal entries, expense and payroll data, vendor master and payment records, and badge or facility-entry data. Capture each extract with its source parameters — system, query, date range, run date, extractor — so the pull is reproducible.\n3. Log every item in the chain-of-custody register at acquisition: unique item ID, collector, source custodian or system, date and time, hash where applicable, and every subsequent transfer. Gaps in the chain are what opposing counsel attacks first.\n4. Preserve originals unaltered in the evidence store; analyze working copies only, and verify the working copy's hash matches the original before analysis starts.\n5. Store everything in the restricted case repository under the case's access list; no evidence on laptops, personal drives, or in email. Reconcile collected items against the custodian list and the workplan — every planned source is either collected or its absence explained.\n\n*Execute forensic analytics and document examination.* Establish what took place, over what period, and by whom — through analytics, document examination, and background checks that another examiner could re-perform from the same evidence and reach the same result.\n\n6. Run forensic data analytics keyed to the alleged scheme, recording parameters so every run is reproducible. Core battery: journal-entry testing across the scheme window (entries posted outside business hours or by unexpected users, round-dollar amounts, period-end postings to seldom-used or suspense accounts, amounts just below approval thresholds); vendor-to-employee matching on address, bank account, tax ID, and phone; duplicate and split payments — especially sequences split just under delegation-of-authority limits; and segregation-of-duties breaks between the actors in the theory, such as the same user creating a vendor and approving its invoices.\n7. Follow the anomalies, not the volume: rank hits by proximity to the fraud theory, resolve each to corroborating documents, and record dead ends as tested-and-cleared — a workpaper that shows only hits reads as confirmation bias.\n8. Examine key documents for authenticity and alteration: metadata against claimed dates, font and layout breaks, signature comparison, and sequence gaps in numbered instruments. Route contested documents to a specialist rather than concluding on visual inspection alone.\n9. Run background and public-records checks on subjects and implicated counterparties: corporate registrations and officers (shell-company indicators: recent formation, residential or mail-drop address, no operational footprint), litigation and lien history, and undisclosed business interests connecting a subject to a vendor.\n10. Retrospectively verify that pre-employment screening operated for implicated personnel; record missing or stale screening as a control exception in its own right.\n11. Reconstruct the event timeline linking actors, transactions, communications, and records — the timeline is the backbone the interviews will test.\n\n**Record in AssureSwarm**\nRe-attach the maintained chain-of-custody register and the acquisition records (hashes, source parameters) as step documents; upload each evidence extract as a step document into the restricted case repository (originals sealed, analysis on verified copies only).\n- Record collection completeness on this step: custodian-list sources collected, outstanding, or documented as unavailable.\n\nAttach the analytic scripts and parameters and the results workpapers (XLSX), the document-examination notes, background-check reports, and the timeline (DOCX/PDF) as step documents.\n- Log control exceptions (missing/stale pre-employment screening, segregation-of-duties breaks) as **Issue** items (`issue_type: exception`, `source: internal_audit`) linked to the affected **Control** (Issue ↔ Control); maintain the evidence map tying each fraud-theory element to its support as a step document.\n\n**Exit criteria**\nEvery planned source is collected or its absence explained; every item carries a complete custody record with a hash where applicable; originals are sealed and analysis runs on verified copies only; repository access is limited to the named team.\n\nEach fraud-theory element is corroborated, refuted, or marked open with the evidence gap named; analytics are reproducible from recorded parameters; anomalies are resolved or assigned; the timeline reconciles with the documentary record.\n\n> **⚡ Audit Artist accelerator:** `/sox-python` runs the journal-entry, duplicate-payment, and vendor-to-employee matching analytics as reproducible, parameter-logged procedures a reviewer can re-execute.","label":"Execute forensic analytics and document examination","performedBy":{"primitives":["coach-document-upload","coach-item-create","sox-python"]}},"id":"execute-forensic-procedures"},{"data":{"description":"Interview witnesses in sequence from peripheral to proximate","instructions":"**Objective** — Corroborate and extend the documentary evidence through witness interviews sequenced so each conversation informs the next without alerting the subject or contaminating testimony.\n\n**Inputs**\n- The event timeline, evidence map, and open-question list from the forensic procedures.\n- The witness list ranked peripheral-to-proximate; the privilege posture and the admonition scripts agreed with counsel.\n- Interview logistics that preserve confidentiality: neutral rooms, code-named invitations.\n\n**Procedure**\n1. Sequence interviews from peripheral witnesses (records custodians, process performers) toward those closest to the alleged conduct, and interview witnesses before any subject. Plan each so nothing said in it can travel to the subject before you are ready — give the confidentiality admonition at the start and repeat it at close.\n2. Prepare a written plan per witness keyed to the evidence they can speak to: the documents to show, the timeline segments they can confirm, and the open questions they can close. An interview without an evidence-keyed plan is a conversation, not a procedure.\n3. Conduct with two investigators present — one leading, one taking near-verbatim notes. Deliver the agreed admonitions, including the counsel-directed script where the investigation is privileged, and remind reporters and witnesses of anti-retaliation protections explicitly.\n4. Ask open questions before showing documents: obtain the witness's uncontaminated account first, then test it against the record. Note facts extensively and demeanor sparingly; distinguish first-hand knowledge from hearsay in the memo.\n5. Prepare the contemporaneous interview memorandum within 24 hours: attendees, date, admonitions given, the account in substance, documents shown, and verbatim quotes for critical statements. Mark it per the privilege convention.\n6. After each interview, update the evidence map and open-question list and reassess sequencing — a witness who proves closer to the conduct than expected may need to move behind others.\n\n**Record in AssureSwarm**\n- Attach the interview plans and the privilege-marked contemporaneous memoranda as step documents; cross-reference each memorandum to the timeline segments and evidence items it corroborates or contradicts.\n- Keep the open-question list current as a step document, updated after each interview.\n\n**Exit criteria** — Every planned witness interviewed or the omission justified; memoranda are contemporaneous with admonitions documented; the evidence map is updated; no subject has been interviewed yet; anti-retaliation reminders are recorded.","label":"Conduct witness interviews"},"id":"conduct-witness-interviews"},{"data":{"description":"Interview the subject last with counsel-directed admonitions","instructions":"**Objective** — Give each subject a fair, structured opportunity to respond to the evidence — conducted last, under counsel direction, without compromising evidence still uncollected or the organization's legal position.\n\n**Inputs**\n- The complete evidence package: timeline, analytics, documents, witness memoranda.\n- Counsel's decisions on timing, attendees, and admonitions, plus any HR action (suspension, access revocation) planned for immediately after.\n- The open-question list: what only the subject can explain.\n\n**Procedure**\n1. Coordinate timing, attendees, and required admonitions with counsel consistent with the privilege posture. Where counsel directs the interview, deliver the corporate-representation admonition — the interviewers and counsel represent the organization, not the individual, and the privilege is the organization's to waive — and record that it was given.\n2. Gate readiness first: confirm the evidence package is complete enough that the interview cannot serve as the subject's discovery of what has not yet been collected. Anything preservable but uncollected gets preserved before the interview is scheduled.\n3. Structure the interview from the periphery inward: background and role, the process as the subject describes it, then present key evidence item by item for explanation. Let every explanation be offered before confronting contradictions; document admissions, denials, and new assertions verbatim in a contemporaneous memorandum prepared within 24 hours.\n4. Make no threats and no promises — of leniency, confidentiality, or employment outcome; a coerced account is worthless in every later forum. Offer the subject the chance to provide records or names supporting their account, and follow up on each.\n5. Assess immediately after: do new assertions or leads require additional preservation, collection, or witness re-interviews before findings are drafted? Coordinate any pre-planned HR action so it executes right after the interview, never before it.\n6. Reaffirm confidentiality obligations at close, and log any retaliation-risk concerns raised.\n\n**Record in AssureSwarm**\n- Attach the interview plan, the admonition record, and the privilege-marked contemporaneous memorandum as step documents; record new leads as follow-up items or preservation actions on this step.\n- Record the subject-response status per allegation element in the interview memorandum (Audit has no native field for it).\n\n**Exit criteria** — Subjects interviewed last with counsel-directed admonitions documented; the memorandum is contemporaneous with verbatim critical statements; new leads are dispositioned (preserved, collected, or declined with reason); no threats or promises were made; follow-on HR coordination executed as planned.","label":"Conduct subject interview"},"id":"conduct-subject-interview"},{"data":{"description":"Conclude on substantiation, quantify losses, and root-cause the control breakdown","instructions":"**Objective** — Conclude on each allegation element against the approved criteria and quantify the loss with a documented method — so reporting, referral, discipline, and recovery decisions rest on evidence, not impression.\n\n**Inputs**\n- The full evidence set: analytics workpapers, documents, timeline, witness and subject memoranda.\n- The evaluation criteria from the approved workplan: the policies, delegation limits, and legal provisions cited.\n- The chain-of-custody register, for a completeness check before concluding.\n\n**Procedure**\n1. Conclude substantiated, unsubstantiated, or inconclusive for each allegation element separately — a case is rarely one verdict. Apply a consistent evidence standard (for internal purposes, preponderance: more likely than not) and state which standard was applied. Document each conclusion as condition (what happened, per the evidence), criteria (the specific policy, delegation limit, or legal provision violated), cause (how it was possible), and effect (loss, misstatement, exposure).\n2. Write findings in facts, not legal conclusions: describe the conduct — \"submitted 14 invoices totaling $212,400 from a vendor he beneficially owned, approved under his own delegation\" — and leave the label \"fraud\" to counsel and the courts.\n3. Quantify direct losses transaction by transaction where the records permit, tying each amount to evidence items. Where extrapolation beyond the tested window is necessary, present it separately as an estimate with its method and assumptions — never blend proven and estimated amounts into one number. State gross loss, expected recoveries (restitution, insurance), and investigation cost separately.\n4. Identify the control breakdowns and overrides that allowed the scheme, tracing each to the specific anti-fraud control that failed to prevent or detect it, and classify how it failed — design gap, non-operation, or deliberate override. The distinction drives remediation versus discipline.\n5. Draft recommendations addressing the root causes, not the symptoms: an override by a senior approver is a governance problem, and adding a form does not fix it.\n6. Complete supervisory review of the workpapers and conclusions — evidence-to-conclusion trace, quantification math, criteria citations — before anything is communicated beyond the team.\n\n**Record in AssureSwarm**\n- Attach the findings memorandum (DOCX/PDF) and the loss-quantification schedule (XLSX, with method and assumptions) as step documents; cross-reference each finding to its evidence items and the affected **Control** records.\n- Summarize per-element conclusions and quantified amounts (proven versus estimated) in the memorandum, and set the case Audit item `rating` to reflect the overall outcome; record the supervisory reviewer and date on this step.\n\n**Exit criteria** — Every allegation element carries a conclusion with condition, criteria, cause, and effect and an evidence trace; loss figures separate proven from estimated with methods documented; each control breakdown maps to a named control; supervisory review is signed before any external communication.","label":"Develop findings and quantify loss"},"id":"develop-findings-and-quantify-loss"},{"data":{"decisionField":"referral_path","description":"Approve the privilege-protected committee report and decide each regulatory, insurance, contractual and law-enforcement referral obligation and deadline.","formData":{"fields":[{"key":"referral_path","label":"Determine external referral","options":[{"label":"Regulatory or law-enforcement referral required","value":"external_required"},{"label":"Handle internally, no external referral","value":"internal_only"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Approve the privilege-protected committee report and decide each regulatory, insurance, contractual and law-enforcement referral obligation and deadline.\n\n**Inputs**\nThe reviewed findings memorandum, loss quantification, and control-breakdown analysis.\n- The privilege posture and counsel's routing instructions; the audit committee's reporting calendar and format expectations.\n- Management's proposed personnel and containment actions.\n\n**Decision criteria**\n*The agent prepares the combined evidence and performs the recordkeeping below. General counsel with Chief Audit Executive and audit committee input owns the stated judgments and authorizations.*\n\n*Report to audit committee and legal.* Put the investigation's results in front of the audit committee and legal counsel accurately, objectively, and in a form that preserves privilege — this report is the record the organization will act on and defend.\n\n1. Route the report through counsel where the privilege posture requires it: counsel reviews privilege markings, legal characterizations, and distribution before anyone else sees it. Number the copies or restrict the distribution list — committee fraud reports do not circulate.\n2. Brief the audit committee or its delegate on: the substantiation conclusions per element, the quantified loss (proven versus estimated, and expected recovery), the subjects' employment status and pending actions, the control breakdowns and overrides that allowed the scheme, and management's proposed actions — with internal audit's view of whether they address root cause.\n3. Verify the communication against the quality bar before issue: accurate (every number traces to a workpaper), objective (facts and conclusions, no advocacy), clear, concise, constructive, complete (adverse facts included — an omitted bad fact discovered later destroys credibility), and timely.\n4. Protect the reporter: nothing in the report or briefing may identify a confidential reporter directly or by inference through role, timing, or unique knowledge.\n5. Agree with counsel the timing and ownership of any employee, customer, or press communications, so the organization speaks once and consistently.\n6. Record the obligation that survives issuance: if a significant error or omission is later found, the corrected information is communicated to everyone who received the original.\n\n*Determine external referral.* Decide with counsel whether the substantiated conduct triggers a regulatory filing, an insurer notification, or a law-enforcement referral, or is handled internally — so external obligations are met deliberately and on time rather than missed by default. Owned by general counsel, with CAE and audit-committee input recorded.\n\n\n\n**external_required** (Regulatory or law-enforcement referral required) — any of the following holds: a statutory or regulatory reporting duty applies to the conduct or the entity (suspicious-activity or fraud reporting in regulated financial businesses, government-contract or public-funds theft reporting, sector-specific regulator notification rules); the fidelity or crime-insurance policy requires notice of a discovered loss within a stated window — insurer notice periods are short and missing them forfeits recovery, so a quantified loss with coverage triggers this branch on its own; the organization elects law-enforcement referral for prosecution, restitution, or deterrence; disclosure or external-auditor obligations identified with counsel require communication outside the organization; or a customer or counterparty contract mandates notification of employee dishonesty affecting them.\n- **internal_only** (Handle internally, no external referral) — counsel concludes no mandatory reporting or notice obligation applies (documented, not assumed), no insurance recovery is being pursued or no coverage exists, and the weighed judgment — recovery prospects, litigation cost and duration, publicity, employee-relations impact, deterrence value — favors resolving through discipline, restitution agreements, and control remediation. The rationale must show the obligations checklist was actually run; \"we would rather not\" without the checklist is not a defensible internal-only call.\n\nDecide per external party, not once for the case: an insurer notice can be required while a law-enforcement referral is declined.\n\n**Record in AssureSwarm**\nAttach the issued fraud report and briefing materials (privilege-marked, DOCX/PDF) with the distribution list and the counsel-review evidence as step documents.\n- Set the case Audit item `report_date`; record the briefing date, attendees, and committee direction on this step, and log the correction obligation and the communication-plan owner there.\n\nSubmit this step's form: `referral_path` = the chosen branch; the step result = the obligation categories reviewed (regulatory, insurance, contractual, disclosure) with counsel's conclusion on each and the deadline dates where they exist; the step's approver record = the counsel owner, with CAE and committee concurrence noted.\n\n**Exit criteria**\nReport issued through the counsel-approved route; the committee is briefed with its direction recorded; quality criteria verified; reporter identity protected; external-communication ownership agreed; the correction obligation is logged.\n\nForm submitted; the rationale shows each obligation category checked with counsel's conclusion; deadlines captured for any required filing; the unused branch is prunable.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the committee briefing package — findings, quantification, and control-breakdown exhibits — into a single distribution-ready document with consistent privilege markings.","kind":"decision","label":"Determine external referral","performedBy":{"primitives":["coach-render-package","coach-document-upload"]}},"id":"determine-external-referral"},{"data":{"description":"Execute the counsel-approved regulatory, insurer, or law-enforcement referral","instructions":"**Objective** — Execute every counsel-approved external referral within its deadline while keeping evidence integrity and privilege intact — a late insurer notice forfeits recovery, and a sloppy production waives privilege.\n\n**Inputs**\n- The referral decision with per-party obligations and deadlines.\n- The findings memorandum, loss quantification, and the evidence repository with its chain-of-custody register.\n- The fidelity or crime-insurance policy's notice and proof-of-loss provisions; counsel's approved referral package templates.\n\n**Procedure**\n1. Prepare a counsel-approved package per external party — regulator, insurer, law enforcement — containing what that recipient needs and nothing more. Redact privileged material, unrelated-employee data, and confidential-reporter information before anything leaves; log what was redacted and why.\n2. File regulatory notifications within their statutory windows; calendar each deadline with a named owner and retain proof of submission — portal receipt or delivery confirmation.\n3. Notify the fidelity or crime insurer within the policy's notice period as soon as loss discovery is established — do not wait for final quantification; supplement later. Track the separate proof-of-loss deadline (commonly 60–120 days from discovery) and request extensions in writing where quantification will run long.\n4. Establish a single law-enforcement liaison; all requests and productions run through that person. Produce evidence only as working copies under the chain-of-custody procedures — originals stay in the evidence store, and every production is logged with items, hashes, date, and recipient — so the organization can prove exactly what it handed over.\n5. Log every external communication with date, audience, and content summary; ad-hoc calls with a regulator or investigator are memorialized the same day.\n6. Track each referral obligation to completion: filed, acknowledged, supplemented as required, closed. An obligation without an owner and a next date is an obligation about to be missed.\n\n**Record in AssureSwarm**\n- Attach each referral package as produced (post-redaction), the submission proofs, and the production log with hashes as step documents; re-attach the maintained chain-of-custody register here (productions logged).\n- Keep the obligations tracker (party, deadline, owner, status) as a step document, and log every external communication as a dated entry on this step.\n\n**Exit criteria** — Every required filing submitted within its window with proof retained; insurer notice and proof-of-loss clocks satisfied or extended in writing; all productions logged under chain of custody with originals retained; open obligations carry owners and next dates.\n\n> **⚡ Audit Artist accelerator:** `/coach-redact` produces the redacted referral copies — stripping privileged passages, reporter-identifying details, and unrelated-employee data — with a redaction log per package.","label":"Execute regulatory or law-enforcement referral","performedBy":{"primitives":["coach-redact","coach-document-upload"]}},"id":"execute-external-referral"},{"data":{"description":"Hand off control-gap findings to Finding Remediation & Action-Plan Monitoring and SOX Deficiency Remediation","instructions":"**Objective** — Route every control breakdown the investigation exposed into owned, tracked remediation — findings that close inside a confidential case file fix nothing and recur.\n\n**Inputs**\n- The control-breakdown analysis: each failed or overridden control with its evidence and root cause.\n- The findings memorandum and recommendations; management's committed actions from the committee briefing.\n- Owners in the receiving workflows: Finding Remediation & Action-Plan Monitoring, SOX Deficiency Remediation, and the fraud-risk-assessment owner.\n\n**Procedure**\n1. Register each control-gap finding as its own record: the control that failed, how it failed (design gap, non-operation, or deliberate override), the evidence reference, root cause, accountable owner, and the recommended action. Strip investigation-confidential detail the remediation audience must not see — the finding has to stand on sanitized facts.\n2. Hand the findings package to Finding Remediation & Action-Plan Monitoring for action-plan tracking and evidence-based closure, and obtain the receiving owner's acknowledgment so accountability transfers explicitly.\n3. Where a breakdown affects internal control over financial reporting, open SOX Deficiency Remediation so severity evaluation (deficiency, significant deficiency, material weakness) and remediation follow the ICFR path — fraud by a control performer or an override of a key control is a severity input the SOX team must weigh, not a footnote.\n4. Feed the scheme pattern, red flags, and override techniques to the next Fraud Risk Assessment & Anti-Override Control Review cycle: how the scheme worked, which anti-fraud controls it defeated and how, and which monitoring rule would have caught it earlier.\n5. Confirm recommended disciplinary actions for substantiated violations entered the formal disciplinary process, and record the sanctions applied and their documentation — consistent discipline is itself an anti-fraud control whose operation this step evidences.\n\n**Record in AssureSwarm**\n- Create one **Issue** item per control breakdown — `issue_type: finding` for a control gap, or `deficiency`/`significant_deficiency`/`material_weakness` for ICFR-affecting ones — setting `source: internal_audit`, `severity`, `root_cause`, `recommendation`, `issue_owner`, and `identified_date`, and link each to the failed **Control** and to the case **Audit** item (Issue ↔ Control, Issue ↔ Audit). These sanitized Issue items ARE the handoff package Finding Remediation & Action-Plan Monitoring and SOX Deficiency Remediation anchor on.\n- Attach the sanitized handoff packages and the receiving-owner acknowledgments as step documents; investigation-confidential detail stays in the step documents, never on the Issue.\n- Record the disciplinary-process entries and sanction outcomes, and attach the scheme-intelligence memo (scheme pattern, red flags, override techniques) destined for the next Fraud Risk Assessment & Anti-Override Control Review as a step document.\n\n**Exit criteria** — Every control breakdown exists as an owned finding with an acknowledged receiving workflow; ICFR-relevant breakdowns have a SOX Deficiency Remediation case open; scheme intelligence is delivered to the fraud-risk owner; disciplinary outcomes are recorded.","label":"Hand off remediation and control gaps"},"id":"handoff-remediation-and-control-gaps"},{"data":{"description":"Approve financial-statement, certification and disclosure conclusions and direct recovery and investigation-method improvements.","instructions":"**Objective** — Approve financial-statement, certification and disclosure conclusions and direct recovery and investigation-method improvements.\n\n**Inputs**\nThe findings memorandum, loss quantification (proven and estimated), and the affected accounts and periods.\n- Counsel and CFO availability; the external auditor's communication protocol.\n- Recovery status — insurer claim, restitution agreements — and the intake and triage records for calibration review.\n\nThe complete file for the selected case path: intake and triage evidence plus the applicable custody register, workpapers, memoranda, reports, referral and handoff records. A referred or predication-closed case retains only artifacts actually produced; do not invent investigation results.\n- Active litigation holds and open referral obligations; the retention schedule.\n- Final dispositions: findings, referrals, disciplinary and recovery outcomes.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Financial Officer and general counsel with investigation lead owns the stated judgments and authorizations.*\n\n*Evaluate disclosure and capture lessons.* Complete the closure obligations that outlive fieldwork: the financial-statement and disclosure evaluation, recovery tracking, and the lessons that make the next intake, detection, and investigation better.\n\n1. Evaluate with counsel and the CFO whether the substantiated conduct has financial-statement implications: misstatement of prior periods (error correction versus out-of-period adjustment, with materiality assessed quantitatively and qualitatively — fraud involving management weighs qualitatively even at small amounts), required disclosures, and what must be communicated to the external auditor. Record the conclusion and its basis either way; an undocumented \"immaterial\" is the first thing a later restatement review seizes on.\n2. Where the organization files certified financial reports, confirm the certification impact is considered: whether the control breakdowns change the ICFR effectiveness assessment already moving through SOX Deficiency Remediation.\n3. Track recovery to conclusion, not to filing: insurer claim status against policy deadlines, restitution agreement performance, and net-recovery accounting, with follow-ups diarized.\n4. Run the lessons-learned review while the team is intact: intake and triage calibration (was predication assessed too slowly or too leniently?), detection gaps that should become monitoring rules (which analytic from this case should run continuously?), and investigation-process improvements (preservation speed, privilege handling, interview sequencing).\n5. Update the investigation procedures and predication criteria where the case exposed weaknesses, and route monitoring-rule candidates to the fraud-risk and monitoring owners with the supporting case evidence.\n\n*Close and archive.* Close the engagement with the case file preserved as an immutable, privilege-intact record, every linked obligation dispositioned, and follow-ups scheduled — so the file can be reopened, produced, or relied on years later without reconstruction.\n\n6. Verify completion honestly: every step finished or explicitly dispositioned, decision forms submitted, handoffs acknowledged, and external obligations either closed or carried by a named owner with a next date. Closing over an open obligation is how insurer deadlines and re-test commitments get missed.\n7. Archive the complete file produced on this selected case path with privilege markings and access restrictions intact — archiving never means relaxing access. The confidentiality ring survives closure.\n8. Confirm nothing subject to an active litigation hold or referral obligation is destroyed; set the retention clock from the last obligation to lapse (hold release, claim settlement, end of prosecution), not from the case close date, and record counsel's written hold-release instruction when it comes.\n9. Update the linked records with the final disposition: findings status, referral outcomes, disciplinary records, and the allegation record back at intake — so the hotline's history and any future predication assessment see how this matter ended.\n10. Communicate closure to the accountable stakeholders — the CAE, general counsel, the audit-committee record, and the receiving workflow owners — without expanding the confidentiality ring.\n11. Schedule the follow-up checkpoints that outlive the case: remediation progress in Finding Remediation & Action-Plan Monitoring, SOX Deficiency Remediation severity outcomes, and external-referral and recovery milestones. Lock the workflow record; post-closure edits happen as documented amendments, never silent changes.\n\n**Record in AssureSwarm**\nAttach the disclosure-evaluation memo (counsel and CFO sign-off) and the lessons-learned record as step documents; record recovery status with owners and next dates on this step.\n- Log procedure and criteria updates against the investigation-protocol documents, and route monitoring-rule candidates to their receiving owners as part of the scheme-intelligence handoff.\n\nArchive the workflow instance as the durable audit trail and set the case **Audit** item to its final status with access restrictions intact; record the retention basis, hold status, and closure-communication recipients with dates on this step.\n- Confirm the linked **Issue** (findings), referral, disciplinary, and recovery records reflect final dispositions, and update the allegation record back at intake; schedule the follow-up checkpoints.\n\n**Exit criteria**\nDisclosure conclusion documented with counsel and CFO sign-off, including the no-impact case; recovery tracking is live with owners and dates; lessons are captured across intake, detection, and process; protocol updates are routed.\n\nAll steps and obligations dispositioned; the case file is archived with privilege and access controls intact; retention is anchored to the last obligation to lapse; linked records are final; follow-ups are scheduled with owners; the record is locked against silent edits.","label":"Evaluate disclosure and capture lessons"},"id":"evaluate-disclosure-and-lessons"}],"sourceTemplateId":"workflow-library:audit-fraud-investigation"}
