Skip to content
← Services

04

Compliance and internal investigations

A report of questionable payments comes in. The head of purchasing finds irregularities involving a business partner. Or management wants to know whether existing controls are still sufficient after an acquisition. The occasion determines which review is required and how far it should go.

PBL Legal advises companies on compliance management systems and internal investigations. We support the clarification of specific suspected cases and the legal assessment of the findings. We also develop and revise rules and procedures for preventing breaches.

On this page

Defining the investigation mandate

At the beginning, the matter to be investigated is defined, as are the affected companies and who may give the mandate. If a report contains allegations against management, it must also be clarified who commissions the investigation and who receives its results.

An investigation plan records which questions are to be answered and which information is needed for them. It must be capable of adjustment to new findings. A matter that is initially narrowly limited can raise further questions; conversely, a suspicion may be refuted by the available documents.

Establishing facts and assessing them legally

In the evaluation, a distinction must be made between a documented matter, a statement and an assumption that has not yet been reviewed. For example, a payment may be documented while its purpose or the basis for its approval remains open. Only further clarification allows a legal classification.

Before employee data is secured and evaluated, the legal requirements must be clarified. Data protection and participation rights of employee representative bodies belong in the investigation planning. A suspicion does not allow unlimited access to all documents and communication data.

The findings should show what was established, what the findings are based on and which questions remain open. This gives the responsible bodies a basis for deciding on further measures. If the findings concern the responsibility of directors or board members, a separate liability review follows.

Investigations across borders

In cross-border matters, data, witnesses and decision-makers may be distributed among several companies. The local legal requirements and the responsibilities of the advisers involved must then also be clarified. This concerns, for example, access to documents and their transfer between countries.

Dr. Andreas Lohner assists with cross-border internal investigations. His areas of focus also include D&O liability and compliance management systems.

Reviewing a compliance system against actual processes

A policy may require an approval without it being clear in operations who grants it. A business partner may have been checked at the start of the contract although its owners or activities later changed. Such situations show why the actual processes have to be considered when a compliance system is reviewed.

PBL analyzes compliance risks and supports codes of conduct, anti-corruption programs and procedures for business partner reviews. This also includes training for executives, management and supervisory bodies. For an existing system, the work can be limited to a specific process or business area.

An investigation can lead to specific changes: different approval responsibilities, additional checks or adjusted reporting channels. Which measures are appropriate must be derived from the findings and the company's risks.

Typical situations

General advisory situations, not client references.

A payment to an intermediary raises questions

During an internal review, a payment stands out whose description of services is unclear. An employee suspects a connection with the award of a contract. Whether the suspicion is correct remains open.

PBL defines the questions to be investigated with the instructing party and clarifies the legal requirements for securing and evaluating documents. The contract, payment approval and further findings are considered in context. The assessment records which matters are documented, which explanations exist and what requires further clarification.

Different approval rules apply after an acquisition

A corporate group has acquired another company. While the group reviews certain business partners before the start of a contract, the new subsidiary uses different approvals and documentation.

We compare the existing procedures and examine which differences are relevant legally and for the respective risks. On that basis, responsibilities, review requirements and reporting channels are coordinated. Simply adopting the group policy would not yet clarify who actually performs and documents the reviews at the subsidiary.

Frequently asked questions

Does every report justify a full investigation?

The content and significance of the report must first be assessed. The scope and sequence of the clarification depend on the specific occasion. Existing documents may be decisive for this initial assessment.

Can we have email mailboxes evaluated immediately?

Before an evaluation, the legal requirements, purpose and scope must be reviewed. It must also be determined who may access the data. This applies even if the suspicion is serious.

What happens if an allegation is not confirmed?

The result must be recorded accordingly. A distinction must be made between whether the allegation was refuted or whether the available information does not allow a final finding. An open question must not appear in the report as a proven breach.

Do we have to rebuild our compliance system completely?

That only follows from the review. Often, the mandate initially concerns a specific business process or an identified weakness. Existing rules and responsibilities are included.

Contact

For the first contact, please describe the occasion, the affected companies and any dates already known.

Contact partner: Dr. Andreas Lohner

+49 89 541 9401 50

andreas.lohner@pbl-legal.de